Skip to content

Commit b065bfc

Browse files
committed
ci: switch PyPI publish to OIDC and fix release tagging
- Drop PYPI_API_TOKEN; rely on Trusted Publisher (id-token + pypi env already configured). - Read version from pyproject.toml and skip publish if the version is already on PyPI (avoids failing runs on every push to main). - Tag the release commit as v<version> and create the GitHub release with that tag and auto-generated notes (previously used github.ref_name which resolves to "main" under workflow_run). - Bump runner Python to 3.11 so tomllib is available.
1 parent 2e2e083 commit b065bfc

2 files changed

Lines changed: 56 additions & 22 deletions

File tree

‎.github/workflows/publish.yml‎

Lines changed: 53 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -16,28 +16,52 @@ permissions:
1616

1717
jobs:
1818
release-build:
19+
if: ${{ github.event.workflow_run.conclusion == 'success' }}
1920
runs-on: ubuntu-latest
21+
outputs:
22+
version: ${{ steps.version.outputs.version }}
23+
should_publish: ${{ steps.check.outputs.should_publish }}
2024
steps:
21-
- uses: actions/checkout@v4
25+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2226
name: ⬇️ Checkout repository
23-
- uses: actions/setup-python@v5
27+
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
2428
name: 📦 Setup Python
2529
with:
26-
python-version: "3.9"
27-
cache: "pip" # caching pip dependencies
30+
python-version: "3.11"
31+
cache: "pip"
32+
- name: 🔢 Read version
33+
id: version
34+
run: |
35+
VERSION=$(python -c "import tomllib; print(tomllib.loads(open('pyproject.toml','rb').read().decode())['project']['version'])")
36+
echo "version=$VERSION" >> "$GITHUB_OUTPUT"
37+
- name: 🔎 Check if already published
38+
id: check
39+
env:
40+
VERSION: ${{ steps.version.outputs.version }}
41+
run: |
42+
if curl -fsSL "https://pypi.org/pypi/geothai/${VERSION}/json" >/dev/null 2>&1; then
43+
echo "should_publish=false" >> "$GITHUB_OUTPUT"
44+
echo "ℹ️ geothai ${VERSION} already on PyPI; skipping publish."
45+
else
46+
echo "should_publish=true" >> "$GITHUB_OUTPUT"
47+
fi
2848
- name: 🔍 Install dependencies
49+
if: steps.check.outputs.should_publish == 'true'
2950
run: |
3051
python -m pip install --upgrade pip
3152
pip install -r requirements.txt
3253
- name: 🏗 Build release
54+
if: steps.check.outputs.should_publish == 'true'
3355
run: python -m build
34-
- uses: actions/upload-artifact@v4
56+
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
57+
if: steps.check.outputs.should_publish == 'true'
3558
name: 📤 Upload artifact
3659
with:
3760
name: release
3861
path: dist/
3962

4063
pypi-publish:
64+
if: needs.release-build.outputs.should_publish == 'true'
4165
runs-on: ubuntu-latest
4266
needs:
4367
- release-build
@@ -47,39 +71,49 @@ jobs:
4771
name: pypi
4872
url: https://pypi.org/project/geothai
4973
steps:
50-
- uses: actions/download-artifact@v4
74+
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
5175
name: 📥 Download artifact
5276
with:
5377
name: release
5478
path: dist/
55-
- uses: pypa/gh-action-pypi-publish@v1.12.4
79+
- uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0
5680
name: 🚀 Publish package
57-
with:
58-
user: __token__
59-
password: ${{ secrets.PYPI_API_TOKEN }}
6081

6182
github-release:
83+
if: needs.release-build.outputs.should_publish == 'true'
6284
runs-on: ubuntu-latest
6385
needs:
86+
- release-build
6487
- pypi-publish
6588
permissions:
6689
contents: write
6790
id-token: write
91+
env:
92+
VERSION: ${{ needs.release-build.outputs.version }}
93+
GITHUB_TOKEN: ${{ github.token }}
6894
steps:
69-
- uses: actions/download-artifact@v4
95+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
96+
name: ⬇️ Checkout repository
97+
with:
98+
fetch-depth: 0
99+
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
70100
name: 📥 Download artifact
71101
with:
72102
name: release
73103
path: dist/
74-
- uses: sigstore/gh-action-sigstore-python@v3.0.0
104+
- uses: sigstore/gh-action-sigstore-python@04cffa1d795717b140764e8b640de88853c92acc # v3.3.0
75105
name: 🔑 Sign artifact
76106
with:
77107
inputs: dist/*
108+
- name: 🏷 Tag commit
109+
run: |
110+
git config user.name "github-actions[bot]"
111+
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
112+
if ! git rev-parse "v${VERSION}" >/dev/null 2>&1; then
113+
git tag "v${VERSION}"
114+
git push origin "v${VERSION}"
115+
fi
78116
- name: 🚀 Create Release
79-
run: gh release create ${{ github.ref_name }} --repo ${{ github.repository }}
80-
env:
81-
GITHUB_TOKEN: ${{ github.token }}
82-
- name: 🚀 Upload Release Asset
83-
run: gh release upload ${{ github.ref_name }} dist/* --repo ${{ github.repository }}
84-
env:
85-
GITHUB_TOKEN: ${{ github.token }}
117+
run: gh release create "v${VERSION}" --repo "${GITHUB_REPOSITORY}" --generate-notes
118+
- name: 📦 Upload Release Asset
119+
run: gh release upload "v${VERSION}" dist/* --repo "${GITHUB_REPOSITORY}"

‎.github/workflows/test.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,12 @@ jobs:
88
build:
99
runs-on: ubuntu-latest
1010
steps:
11-
- uses: actions/checkout@v4
11+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
1212
name: ⬇️ Checkout repository
13-
- uses: actions/setup-python@v5
13+
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
1414
name: 📦 Setup Python
1515
with:
16-
python-version: "3.9"
16+
python-version: "3.11"
1717
cache: "pip" # caching pip dependencies
1818
- name: 🔍 Install dependencies
1919
run: |

0 commit comments

Comments
 (0)