Repository navigation
148 lines (127 loc) · 4.65 KB
/
Copy pathrelease.yml
File metadata and controls
148 lines (127 loc) · 4.65 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
name: Release & Publish to PyPI
on:
push:
tags:
- 'v*'
permissions:
contents: write
id-token: write
packages: write
jobs:
build-and-publish:
name: Build distribution & Publish to PyPI
runs-on: ubuntu-latest
environment:
name: pypi
url: https://pypi.org/p/promptdiff-eval
permissions:
contents: write
id-token: write
packages: write
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.11"
- name: Install build dependencies
run: |
python -m pip install --upgrade pip
pip install build twine
- name: Build sdist and wheel
run: |
python -m build
- name: Validate distribution packages
run: |
twine check dist/*
- name: Publish package distributions to PyPI
uses: pypa/gh-action-pypi-publish@release/v1
with:
password: ${{ secrets.PYPI_API_TOKEN }}
skip-existing: true
- name: Sign distribution packages with Sigstore
uses: sigstore/gh-action-sigstore-python@v3.4.0
with:
inputs: >-
./dist/*.tar.gz
./dist/*.whl
- name: Install Cosign for container and artifact verification
uses: sigstore/cosign-installer@v3.8.2
- name: Verify package on PyPI and record summary
run: |
PACKAGE_NAME="promptdiff-eval"
echo "### 🚀 PyPI Distribution Summary" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "- **Package:** \`$PACKAGE_NAME\`" >> $GITHUB_STEP_SUMMARY
echo "- **Release Tag:** \`${{ github.ref_name }}\`" >> $GITHUB_STEP_SUMMARY
echo "- **PyPI Project URL:** [https://pypi.org/project/$PACKAGE_NAME/](https://pypi.org/project/$PACKAGE_NAME/)" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "Querying PyPI API for indexed release versions..."
# Polling loop to allow PyPI index CDN to reflect newly published distribution
for i in {1..6}; do
HTTP_STATUS=$(curl -s -o /dev/null -w "%{http_code}" "https://pypi.org/pypi/$PACKAGE_NAME/json" || true)
if [ "$HTTP_STATUS" = "200" ]; then
LATEST_VERSION=$(curl -s "https://pypi.org/pypi/$PACKAGE_NAME/json" | python -c "import sys, json; print(json.load(sys.stdin).get('info', {}).get('version', 'unknown'))" 2>/dev/null || echo "unknown")
echo "✅ Verified package on PyPI! Current indexed version: $LATEST_VERSION"
echo "- **Status:** ✅ Successfully published to PyPI" >> $GITHUB_STEP_SUMMARY
echo "- **Latest PyPI Version:** \`$LATEST_VERSION\`" >> $GITHUB_STEP_SUMMARY
break
else
echo "Attempt $i: PyPI index pending (HTTP $HTTP_STATUS). Retrying in 10s..."
sleep 10
fi
done
echo "Checking available versions via pip index..."
pip index versions "$PACKAGE_NAME" || true
- name: Generate CycloneDX SBOM
uses: anchore/sbom-action@v0
with:
path: .
format: cyclonedx-json
output-file: bom.json
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
files: |
dist/*
bom.json
generate_release_notes: true
draft: false
prerelease: false
docker-build:
name: Build & Push Multi-Arch Docker Image
runs-on: ubuntu-latest
needs: build-and-publish
steps:
- uses: actions/checkout@v4
- name: Set up QEMU
uses: docker/setup-qemu-action@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to GitHub Container Registry
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract Docker metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ghcr.io/${{ github.repository }}
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=raw,value=latest
- name: Build and push multi-arch image
uses: docker/build-push-action@v6
with:
context: .
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max