From c011f658cff9b1c79b4cd3f3728286551d102d7a Mon Sep 17 00:00:00 2001 From: Bo Peng Date: Wed, 9 Sep 2026 13:30:28 -0500 Subject: [PATCH] Publish to PyPI via trusted publishing Replace the token-based python-publish.yml with release.yml, which builds the sdist and wheel in one job and uploads them from a separate job that holds the OIDC id-token permission and is gated on the `pypi` environment. Triggers on `release: published` (so drafts do not publish) and on manual workflow_dispatch. Removes the need for the PYPI_USERNAME/PYPI_PASSWORD secrets. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_011tke9h11djfduXhZ3MsYre --- .github/workflows/python-publish.yml | 31 ------------- .github/workflows/release.yml | 67 ++++++++++++++++++++++++++++ 2 files changed, 67 insertions(+), 31 deletions(-) delete mode 100644 .github/workflows/python-publish.yml create mode 100644 .github/workflows/release.yml diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml deleted file mode 100644 index 94c0016e7..000000000 --- a/.github/workflows/python-publish.yml +++ /dev/null @@ -1,31 +0,0 @@ -# This workflow will upload a Python Package using Twine when a release is created -# For more information see: https://help.github.com/en/actions/language-and-framework-guides/using-python-with-github-actions#publishing-to-package-registries - -name: Upload Python Package - -on: - release: - types: [created] - -jobs: - deploy: - - runs-on: ubuntu-latest - - steps: - - uses: actions/checkout@v2 - - name: Set up Python - uses: actions/setup-python@v2 - with: - python-version: '3.x' - - name: Install dependencies - run: | - python -m pip install --upgrade pip - pip install build twine - - name: Build and publish - env: - TWINE_USERNAME: ${{ secrets.PYPI_USERNAME }} - TWINE_PASSWORD: ${{ secrets.PYPI_PASSWORD }} - run: | - python -m build - twine upload dist/* diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 000000000..e0f3a4fdf --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,67 @@ +# Publish sos to PyPI using PyPI Trusted Publishing (OIDC), no API token needed. +# +# PyPI trusted publisher settings for this workflow: +# PyPI Project Name: sos +# Owner: vatlab +# Repository name: SoS +# Workflow name: release.yml +# Environment name: pypi +# +# https://docs.pypi.org/trusted-publishers/ + +name: Release + +on: + release: + types: [published] + workflow_dispatch: + +permissions: + contents: read + +jobs: + build: + name: Build distributions + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Set up Python + uses: actions/setup-python@v5 + with: + python-version: '3.x' + + - name: Build sdist and wheel + run: | + python -m pip install --upgrade pip build + python -m build + + - name: Check distributions + run: | + python -m pip install --upgrade twine + twine check dist/* + + - uses: actions/upload-artifact@v4 + with: + name: dist + path: dist/ + + publish: + name: Publish to PyPI + needs: [build] + runs-on: ubuntu-latest + environment: + name: pypi + url: https://pypi.org/p/sos + permissions: + id-token: write # required for trusted publishing + steps: + - uses: actions/download-artifact@v4 + with: + name: dist + path: dist/ + + - name: Publish to PyPI + uses: pypa/gh-action-pypi-publish@release/v1