name: Publish to PyPI on: push: tags: - "v*" permissions: contents: read jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 with: python-version: "3.13" - run: pip install build - run: python -m build - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: dist path: dist/ publish: needs: build runs-on: ubuntu-latest environment: release permissions: id-token: write steps: - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: dist path: dist/ - uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0 github-release: needs: publish runs-on: ubuntu-latest permissions: contents: write id-token: write # keyless Sigstore signing (OIDC); no signing key exists steps: - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: dist path: dist/ - name: Sign artifacts with Sigstore (keyless, OIDC) # Produces dist/.sigstore.json bundles next to each wheel/sdist. # The 'gh release create dist/*' step below then attaches them to the # GitHub Release, which is where Scorecard's Signed-Releases check looks. # release-signing-artifacts is disabled: the action's own auto-attach only # fires on a 'release: published' event, but we trigger on 'push: tags', # so we upload the bundles ourselves via the dist/* glob. uses: sigstore/gh-action-sigstore-python@04cffa1d795717b140764e8b640de88853c92acc # v3.3.0 with: inputs: ./dist/*.tar.gz ./dist/*.whl release-signing-artifacts: false - name: Extract latest CHANGELOG section run: | # Grab the topmost "## [...]" block from CHANGELOG.md as release notes. awk '/^## \[/{c++} c==1' CHANGELOG.md | sed '/^---$/d' > release_notes.md echo "Release notes:" && cat release_notes.md - name: Create GitHub Release env: GH_TOKEN: ${{ github.token }} run: | gh release create "${GITHUB_REF_NAME}" \ --title "${GITHUB_REF_NAME}" \ --notes-file release_notes.md \ dist/*