Publishing uses PyPI Trusted Publishing via .github/workflows/publish.yml.
- TestPyPI: trigger manually via
workflow_dispatch - PyPI: push a tag matching
v<project.version>frompython/pyproject.toml
The pypi GitHub environment should require manual approval.
These steps live outside the repository and cannot be derived from code:
- Create
testpypiandpypiGitHub environments in repository settings - Configure each PyPI/TestPyPI trusted publisher to trust this repository, the
publish.ymlworkflow, and the matching GitHub environment name - Keep PyPI/TestPyPI project names aligned with the package name in
pyproject.toml