security(ci): least-privilege token on e2e-wheel workflow + W24 changelog (also carries playbook commit 6b89fcd)
75 lines
2.6 KiB
YAML
75 lines
2.6 KiB
YAML
name: Publish to PyPI
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v*"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
|
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
|
with:
|
|
python-version: "3.13"
|
|
- run: pip install build
|
|
- run: python -m build
|
|
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: dist
|
|
path: dist/
|
|
|
|
publish:
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
environment: release
|
|
permissions:
|
|
id-token: write
|
|
steps:
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
name: dist
|
|
path: dist/
|
|
- uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0
|
|
|
|
github-release:
|
|
needs: publish
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
id-token: write # keyless Sigstore signing (OIDC); no signing key exists
|
|
steps:
|
|
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
name: dist
|
|
path: dist/
|
|
- name: Sign artifacts with Sigstore (keyless, OIDC)
|
|
# Produces dist/<artifact>.sigstore.json bundles next to each wheel/sdist.
|
|
# The 'gh release create dist/*' step below then attaches them to the
|
|
# GitHub Release, which is where Scorecard's Signed-Releases check looks.
|
|
# release-signing-artifacts is disabled: the action's own auto-attach only
|
|
# fires on a 'release: published' event, but we trigger on 'push: tags',
|
|
# so we upload the bundles ourselves via the dist/* glob.
|
|
uses: sigstore/gh-action-sigstore-python@04cffa1d795717b140764e8b640de88853c92acc # v3.3.0
|
|
with:
|
|
inputs: ./dist/*.tar.gz ./dist/*.whl
|
|
release-signing-artifacts: false
|
|
- name: Extract latest CHANGELOG section
|
|
run: |
|
|
# Grab the topmost "## [...]" block from CHANGELOG.md as release notes.
|
|
awk '/^## \[/{c++} c==1' CHANGELOG.md | sed '/^---$/d' > release_notes.md
|
|
echo "Release notes:" && cat release_notes.md
|
|
- name: Create GitHub Release
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
run: |
|
|
gh release create "${GITHUB_REF_NAME}" \
|
|
--title "${GITHUB_REF_NAME}" \
|
|
--notes-file release_notes.md \
|
|
dist/*
|