fix(upload): add required type and optional metadata to analyze input… #77
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish to PyPI | |
| on: | |
| push: | |
| branches: | |
| - main | |
| secrets: | |
| PYPI_API_TOKEN: | |
| required: true | |
| workflow_dispatch: | |
| concurrency: ${{ github.workflow }}-${{ github.ref }} | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| id-token: write | |
| jobs: | |
| release-please: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| release_created: ${{ steps.release.outputs.release_created }} | |
| tag_name: ${{ steps.release.outputs.tag_name }} | |
| steps: | |
| # A push made with GITHUB_TOKEN does not start any workflow, so a release | |
| # PR merged with it lands on main and then nothing publishes. Using the | |
| # PAT keeps the chain alive and also lets CI run on the release PR. | |
| - uses: googleapis/release-please-action@v4 | |
| id: release | |
| with: | |
| token: ${{ secrets.SDK_SYNC_PAT }} | |
| release-type: python | |
| config-file: release-please-config.json | |
| manifest-file: .release-please-manifest.json | |
| # Merging the release PR here, from a push-triggered job, is what makes a | |
| # release land without a human. A pull_request-triggered workflow cannot | |
| # do it: GitHub holds runs on bot-authored PRs as action_required, and it | |
| # never starts CI on a PR the GITHUB_TOKEN opened, so waiting on checks | |
| # would wait forever. | |
| - name: Merge the release PR | |
| env: | |
| GH_TOKEN: ${{ secrets.SDK_SYNC_PAT }} | |
| RELEASE_PR: ${{ steps.release.outputs.pr }} | |
| run: | | |
| # The action's own output is authoritative and immediate. Listing by | |
| # label is not: the previous run created PR #61 at 00:14:03 and a | |
| # label query 3 seconds later still returned nothing, so the release | |
| # sat open. | |
| PR=$(printf '%s' "$RELEASE_PR" | jq -r '.number // empty' 2>/dev/null || true) | |
| if [ -z "$PR" ]; then | |
| for _ in 1 2 3; do | |
| PR=$(gh pr list --repo "$GITHUB_REPOSITORY" --state open --label 'autorelease: pending' \ | |
| --json number,author --jq '[.[] | select(.author.is_bot)] | .[0].number // empty') | |
| [ -n "$PR" ] && break | |
| sleep 5 | |
| done | |
| fi | |
| if [ -z "$PR" ]; then | |
| echo "No pending release PR to merge." | |
| exit 0 | |
| fi | |
| echo "Merging release PR #$PR" | |
| gh pr merge "$PR" --squash --repo "$GITHUB_REPOSITORY" | |
| publish: | |
| needs: release-please | |
| if: ${{ needs.release-please.outputs.release_created }} | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| ref: ${{ needs.release-please.outputs.tag_name }} | |
| - name: Install uv | |
| uses: astral-sh/setup-uv@v4 | |
| - name: Build package | |
| run: uv build | |
| - name: Publish to PyPI | |
| env: | |
| UV_PUBLISH_USERNAME: __token__ | |
| UV_PUBLISH_PASSWORD: ${{ secrets.PYPI_API_TOKEN }} | |
| run: | | |
| uv publish |