|
1 | 1 | name: Release |
2 | 2 |
|
3 | 3 | # Triggered by a version tag (vX.Y.Z). It always builds the distributions, cuts a |
4 | | -# GitHub Release with the wheel + sdist attached, and publishes to PyPI using the |
5 | | -# PYPI_API_TOKEN repository secret. |
| 4 | +# GitHub Release with the wheel + sdist attached, and publishes to PyPI. |
6 | 5 | # |
7 | | -# PyPI auth: the `PYPI_API_TOKEN` secret (set with `gh secret set PYPI_API_TOKEN`, |
8 | | -# value never in source). The publish job runs only on this repository, so forks |
9 | | -# never attempt to publish. To publish an already-tagged version (e.g. after adding |
10 | | -# the token later), use: Actions > Release > Run workflow > enter the tag. |
| 6 | +# PyPI auth: Trusted Publishing (OIDC) - the publish job mints a short-lived |
| 7 | +# identity token; there is no long-lived secret. The Trusted Publisher is |
| 8 | +# registered on PyPI (project `nrdax` > Settings > Publishing) as owner |
| 9 | +# NullRabbitLabs / repo nrdax-python / workflow release.yml / environment pypi, |
| 10 | +# and must match the `environment: pypi` on the publish job below. The publish |
| 11 | +# job runs only on this repository, so forks never attempt to publish. To |
| 12 | +# publish an already-tagged version, use: Actions > Release > Run workflow > |
| 13 | +# enter the tag. |
11 | 14 |
|
12 | 15 | on: |
13 | 16 | push: |
@@ -70,12 +73,18 @@ jobs: |
70 | 73 | # Never publish from forks. |
71 | 74 | if: ${{ github.repository == 'NullRabbitLabs/nrdax-python' }} |
72 | 75 | runs-on: ubuntu-latest |
| 76 | + # Must match the Trusted Publisher registered on PyPI (owner NullRabbitLabs, |
| 77 | + # repo nrdax-python, workflow release.yml, environment pypi). |
| 78 | + environment: |
| 79 | + name: pypi |
| 80 | + url: https://pypi.org/project/nrdax/ |
| 81 | + permissions: |
| 82 | + # OIDC token for PyPI Trusted Publishing (no password/API token). |
| 83 | + id-token: write |
73 | 84 | steps: |
74 | 85 | - uses: actions/download-artifact@v8 |
75 | 86 | with: |
76 | 87 | name: dist |
77 | 88 | path: dist |
78 | 89 | - name: Publish to PyPI |
79 | 90 | uses: pypa/gh-action-pypi-publish@release/v1 |
80 | | - with: |
81 | | - password: ${{ secrets.PYPI_API_TOKEN }} |
|
0 commit comments