96 lines
3.8 KiB
YAML
96 lines
3.8 KiB
YAML
name: Publish to PyPI
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v*"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
# Job-level permissions REPLACE the top-level block rather than merge with
|
|
# it, so `contents: read` is restated here on purpose — dropping it would
|
|
# break actions/checkout. id-token/attestations are what the provenance
|
|
# attestation below needs (Scorecard: Signed-Releases).
|
|
permissions:
|
|
contents: read
|
|
id-token: write
|
|
attestations: write
|
|
steps:
|
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
|
|
with:
|
|
python-version: "3.13"
|
|
# Hash-pinned tool install (Scorecard: Pinned-Dependencies).
|
|
- run: python -m pip install --require-hashes -r .github/requirements/build.txt
|
|
- run: python -m build
|
|
- name: Attest build provenance
|
|
# Signs a provenance statement binding these exact sdist/wheel digests to
|
|
# this workflow run, via the same keyless Sigstore/OIDC path as the
|
|
# release signing below. Runs after the artifacts exist and before they
|
|
# leave the job, so the attested digests are the published ones.
|
|
# NOTE: the bundle is deliberately NOT written into dist/ — the publish
|
|
# job feeds dist/* to gh-action-pypi-publish, which rejects any file that
|
|
# is not a distribution. See the report note on attaching provenance to
|
|
# the GitHub Release.
|
|
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
|
|
with:
|
|
subject-path: "dist/*"
|
|
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: dist
|
|
path: dist/
|
|
|
|
publish:
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
environment: release
|
|
permissions:
|
|
id-token: write
|
|
steps:
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
name: dist
|
|
path: dist/
|
|
- uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0
|
|
|
|
github-release:
|
|
needs: publish
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
id-token: write # keyless Sigstore signing (OIDC); no signing key exists
|
|
steps:
|
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
name: dist
|
|
path: dist/
|
|
- name: Sign artifacts with Sigstore (keyless, OIDC)
|
|
# Produces dist/<artifact>.sigstore.json bundles next to each wheel/sdist.
|
|
# The 'gh release create dist/*' step below then attaches them to the
|
|
# GitHub Release, which is where Scorecard's Signed-Releases check looks.
|
|
# release-signing-artifacts is disabled: the action's own auto-attach only
|
|
# fires on a 'release: published' event, but we trigger on 'push: tags',
|
|
# so we upload the bundles ourselves via the dist/* glob.
|
|
uses: sigstore/gh-action-sigstore-python@5b79a39c381910c090341a2c9b0bf022c8b387e1 # v3.4.0
|
|
with:
|
|
inputs: ./dist/*.tar.gz ./dist/*.whl
|
|
release-signing-artifacts: false
|
|
- name: Extract latest CHANGELOG section
|
|
run: |
|
|
# Grab the topmost "## [...]" block from CHANGELOG.md as release notes.
|
|
awk '/^## \[/{c++} c==1' CHANGELOG.md | sed '/^---$/d' > release_notes.md
|
|
echo "Release notes:" && cat release_notes.md
|
|
- name: Create GitHub Release
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
run: |
|
|
gh release create "${GITHUB_REF_NAME}" \
|
|
--title "${GITHUB_REF_NAME}" \
|
|
--notes-file release_notes.md \
|
|
dist/*
|