Skip to content

Commit 33983a5

Browse files
author
Simon Morley
committed
ci(release): publish to PyPI via Trusted Publishing (OIDC)
The publish job now runs in the 'pypi' environment and mints a short-lived OIDC identity token instead of using the PYPI_API_TOKEN secret. Requires the matching Trusted Publisher on the PyPI project (NullRabbitLabs/nrdax-python, release.yml, environment pypi); the token secret can be deleted once the first OIDC publish succeeds.
1 parent 5cbbcc8 commit 33983a5

1 file changed

Lines changed: 17 additions & 8 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 17 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,16 @@
11
name: Release
22

33
# Triggered by a version tag (vX.Y.Z). It always builds the distributions, cuts a
4-
# GitHub Release with the wheel + sdist attached, and publishes to PyPI using the
5-
# PYPI_API_TOKEN repository secret.
4+
# GitHub Release with the wheel + sdist attached, and publishes to PyPI.
65
#
7-
# PyPI auth: the `PYPI_API_TOKEN` secret (set with `gh secret set PYPI_API_TOKEN`,
8-
# value never in source). The publish job runs only on this repository, so forks
9-
# never attempt to publish. To publish an already-tagged version (e.g. after adding
10-
# the token later), use: Actions > Release > Run workflow > enter the tag.
6+
# PyPI auth: Trusted Publishing (OIDC) - the publish job mints a short-lived
7+
# identity token; there is no long-lived secret. The Trusted Publisher is
8+
# registered on PyPI (project `nrdax` > Settings > Publishing) as owner
9+
# NullRabbitLabs / repo nrdax-python / workflow release.yml / environment pypi,
10+
# and must match the `environment: pypi` on the publish job below. The publish
11+
# job runs only on this repository, so forks never attempt to publish. To
12+
# publish an already-tagged version, use: Actions > Release > Run workflow >
13+
# enter the tag.
1114

1215
on:
1316
push:
@@ -70,12 +73,18 @@ jobs:
7073
# Never publish from forks.
7174
if: ${{ github.repository == 'NullRabbitLabs/nrdax-python' }}
7275
runs-on: ubuntu-latest
76+
# Must match the Trusted Publisher registered on PyPI (owner NullRabbitLabs,
77+
# repo nrdax-python, workflow release.yml, environment pypi).
78+
environment:
79+
name: pypi
80+
url: https://pypi.org/project/nrdax/
81+
permissions:
82+
# OIDC token for PyPI Trusted Publishing (no password/API token).
83+
id-token: write
7384
steps:
7485
- uses: actions/download-artifact@v8
7586
with:
7687
name: dist
7788
path: dist
7889
- name: Publish to PyPI
7990
uses: pypa/gh-action-pypi-publish@release/v1
80-
with:
81-
password: ${{ secrets.PYPI_API_TOKEN }}

0 commit comments

Comments
 (0)