-
Notifications
You must be signed in to change notification settings - Fork 0
99 lines (92 loc) · 3.08 KB
/
Copy pathrelease.yml
File metadata and controls
99 lines (92 loc) · 3.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
name: Release
# Publishing is irreversible: a version can never be re-uploaded to PyPI, even
# after deletion. So the gates below are deliberate - the full test matrix must
# pass, the built artifacts are checked, and the PyPI step waits on a protected
# environment before it runs.
on:
release:
types: [published]
workflow_dispatch:
inputs:
target:
description: Index to publish to
required: true
default: testpypi
type: choice
options: [testpypi, pypi]
permissions:
contents: read
jobs:
verify:
name: Verify ${{ matrix.os }} / Python ${{ matrix.python-version }}
runs-on: ${{ matrix.os }}
strategy:
fail-fast: true
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
python-version: ["3.9", "3.13"]
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
- run: python -m pip install --upgrade pip
- run: pip install -e ".[dev]"
- run: pytest
build:
name: Build distributions
needs: verify
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- run: python -m pip install --upgrade pip build twine
- run: python -m build
- run: twine check --strict dist/*
# A release tag must match the version being published, or the artifact
# and the tag disagree forever.
- name: Check the tag matches the package version
if: github.event_name == 'release'
run: |
set -euo pipefail
version=$(python -c "import tomllib,pathlib;print(tomllib.loads(pathlib.Path('pyproject.toml').read_text())['project']['version'])")
tag="${GITHUB_REF_NAME#v}"
if [ "$version" != "$tag" ]; then
echo "::error::tag $tag does not match project version $version"; exit 1
fi
- uses: actions/upload-artifact@v4
with:
name: dist
path: dist/
publish-testpypi:
name: Publish to TestPyPI
needs: build
if: github.event_name == 'workflow_dispatch' && inputs.target == 'testpypi'
runs-on: ubuntu-latest
environment: testpypi
permissions:
id-token: write # OIDC: trusted publishing, no long-lived token
steps:
- uses: actions/download-artifact@v4
with:
name: dist
path: dist/
- uses: pypa/gh-action-pypi-publish@release/v1
with:
repository-url: https://test.pypi.org/legacy/
publish-pypi:
name: Publish to PyPI
needs: build
if: github.event_name == 'release' || (github.event_name == 'workflow_dispatch' && inputs.target == 'pypi')
runs-on: ubuntu-latest
environment: pypi # protect this in repo settings to require a manual approval
permissions:
id-token: write # OIDC: trusted publishing, no long-lived token
steps:
- uses: actions/download-artifact@v4
with:
name: dist
path: dist/
- uses: pypa/gh-action-pypi-publish@release/v1