-
Notifications
You must be signed in to change notification settings - Fork 1
152 lines (134 loc) · 4.74 KB
/
Copy pathrelease.yml
File metadata and controls
152 lines (134 loc) · 4.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
name: Release
# Publishes ONE package from this monorepo to PyPI.
#
# To release a package, tag it and push the tag:
#
# git tag superred-target-minimal-llm-chat-v0.1.0
# git push origin superred-target-minimal-llm-chat-v0.1.0
#
# The tag format is "<pypi-dist-name>-v<version>". This workflow finds the
# package directory whose pyproject [project].name matches that dist name,
# verifies the version in that pyproject agrees with the tag, builds ONLY that
# package, and publishes it with PyPI Trusted Publishing (OIDC, no API tokens).
#
# Running the workflow manually (Actions -> Release -> Run workflow) publishes
# to TestPyPI instead, as a safe rehearsal.
#
# One-time per package: register a pending publisher on PyPI. See RELEASING.md.
on:
push:
tags:
- "*-v*"
workflow_dispatch:
inputs:
package:
description: "Dist name to rehearse on TestPyPI (e.g. superred-target-minimal-llm-chat)"
required: true
type: string
permissions:
contents: read
jobs:
build:
name: Build
runs-on: ubuntu-latest
outputs:
pkg_name: ${{ steps.resolve.outputs.pkg_name }}
pkg_dir: ${{ steps.resolve.outputs.pkg_dir }}
version: ${{ steps.resolve.outputs.version }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.13"
- name: Resolve which package to release
id: resolve
env:
TAG: ${{ github.ref_type == 'tag' && github.ref_name || '' }}
INPUT_PKG: ${{ inputs.package }}
run: |
python - <<'PY'
import os, sys, tomllib, pathlib
tag = os.environ.get("TAG", "")
if tag:
if "-v" not in tag:
sys.exit(f"::error::Tag {tag!r} is not of the form '<dist-name>-v<version>'")
name, want_version = tag.rsplit("-v", 1)
else:
name, want_version = os.environ["INPUT_PKG"], None
# Map every dist name in the repo to its directory.
found = {}
for p in pathlib.Path(".").rglob("pyproject.toml"):
if ".git" in p.parts:
continue
try:
data = tomllib.loads(p.read_text())
except Exception:
continue
proj = data.get("project", {})
if proj.get("name"):
found[proj["name"]] = (str(p.parent), proj.get("version"))
if name not in found:
sys.exit(
f"::error::No package named {name!r} in this repo. "
f"Known packages: {', '.join(sorted(found))}"
)
pkg_dir, pkg_version = found[name]
if want_version is not None and pkg_version != want_version:
sys.exit(
f"::error::Tag says version {want_version}, but "
f"{pkg_dir}/pyproject.toml says {pkg_version}. "
f"Bump the version to match, then re-tag."
)
with open(os.environ["GITHUB_OUTPUT"], "a") as fh:
fh.write(f"pkg_name={name}\n")
fh.write(f"pkg_dir={pkg_dir}\n")
fh.write(f"version={pkg_version}\n")
print(f"Releasing {name} {pkg_version} from {pkg_dir}")
PY
- name: Build sdist and wheel
run: |
python -m pip install --upgrade build twine
python -m build "${{ steps.resolve.outputs.pkg_dir }}" --outdir dist
- name: Verify metadata renders on PyPI
run: python -m twine check dist/*
- name: Upload distributions
uses: actions/upload-artifact@v4
with:
name: dist
path: dist/
publish-pypi:
name: Publish to PyPI
needs: build
if: github.ref_type == 'tag'
runs-on: ubuntu-latest
environment:
name: pypi
url: https://pypi.org/project/${{ needs.build.outputs.pkg_name }}/
permissions:
id-token: write # required for Trusted Publishing (OIDC)
steps:
- uses: actions/download-artifact@v4
with:
name: dist
path: dist/
- name: Publish to PyPI
uses: pypa/gh-action-pypi-publish@release/v1
publish-testpypi:
name: Publish to TestPyPI (rehearsal)
needs: build
if: github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
environment:
name: testpypi
url: https://test.pypi.org/project/${{ needs.build.outputs.pkg_name }}/
permissions:
id-token: write # required for Trusted Publishing (OIDC)
steps:
- uses: actions/download-artifact@v4
with:
name: dist
path: dist/
- name: Publish to TestPyPI
uses: pypa/gh-action-pypi-publish@release/v1
with:
repository-url: https://test.pypi.org/legacy/