name: Publish to PyPI on: push: tags: - "v*" permissions: contents: read jobs: build: runs-on: ubuntu-latest # Job-level permissions REPLACE the top-level block rather than merge with # it, so `contents: read` is restated here on purpose — dropping it would # break actions/checkout. id-token/attestations are what the provenance # attestation below needs (Scorecard: Signed-Releases). permissions: contents: read id-token: write attestations: write steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 with: python-version: "3.13" # Hash-pinned tool install (Scorecard: Pinned-Dependencies). - run: python -m pip install --require-hashes -r .github/requirements/build.txt - run: python -m build - name: Attest build provenance # Signs a provenance statement binding these exact sdist/wheel digests to # this workflow run, via the same keyless Sigstore/OIDC path as the # release signing below. Runs after the artifacts exist and before they # leave the job, so the attested digests are the published ones. # NOTE: the bundle is deliberately NOT written into dist/ — the publish # job feeds dist/* to gh-action-pypi-publish, which rejects any file that # is not a distribution. See the report note on attaching provenance to # the GitHub Release. uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 with: subject-path: "dist/*" - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: dist path: dist/ publish: needs: build runs-on: ubuntu-latest environment: release permissions: id-token: write steps: - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: dist path: dist/ - uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0 github-release: needs: publish runs-on: ubuntu-latest permissions: contents: write id-token: write # keyless Sigstore signing (OIDC); no signing key exists steps: - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: dist path: dist/ - name: Sign artifacts with Sigstore (keyless, OIDC) # Produces dist/.sigstore.json bundles next to each wheel/sdist. # The 'gh release create dist/*' step below then attaches them to the # GitHub Release, which is where Scorecard's Signed-Releases check looks. # release-signing-artifacts is disabled: the action's own auto-attach only # fires on a 'release: published' event, but we trigger on 'push: tags', # so we upload the bundles ourselves via the dist/* glob. uses: sigstore/gh-action-sigstore-python@5b79a39c381910c090341a2c9b0bf022c8b387e1 # v3.4.0 with: inputs: ./dist/*.tar.gz ./dist/*.whl release-signing-artifacts: false - name: Extract latest CHANGELOG section run: | # Grab the topmost "## [...]" block from CHANGELOG.md as release notes. awk '/^## \[/{c++} c==1' CHANGELOG.md | sed '/^---$/d' > release_notes.md echo "Release notes:" && cat release_notes.md - name: Create GitHub Release env: GH_TOKEN: ${{ github.token }} run: | gh release create "${GITHUB_REF_NAME}" \ --title "${GITHUB_REF_NAME}" \ --notes-file release_notes.md \ dist/*