Repository navigation
89 lines (77 loc) · 3.32 KB
/
Copy pathpublish.yml
File metadata and controls
89 lines (77 loc) · 3.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
name: Publish to PyPI
# Runs the full CI suite against the tagged commit, builds the sdist + wheel, and
# uploads to PyPI whenever a version tag (v0.9.0, v1.0.0, ...) is pushed. A red CI
# blocks the upload. Authentication is PyPI "Trusted Publishing"
# (OIDC) — there is no API token or secret stored in the repo; PyPI is
# configured (Account -> Publishing) to trust this exact workflow file in
# czei/scrollkit, gated on the `pypi` environment.
#
# Release procedure: bump `version` in pyproject.toml AND `__version__` in
# src/scrollkit/__init__.py, update CHANGELOG.md, commit, then:
# git tag v<version> && git push scrollkit master --tags
on:
push:
tags: ["v*"]
jobs:
ci:
# THE RELEASE GATE. The full CI suite must pass on the TAGGED commit before
# anything is uploaded. This is not redundant with ci.yml's own push trigger:
# that trigger fires on branch pushes only, so a tag pointing at an untested
# commit — or at a commit whose CI went red — used to publish regardless.
# 0.9.2 and 0.9.3 both shipped to PyPI on a failing CI run. PyPI versions are
# immutable, so the only fix for a bad upload is burning the next number.
uses: ./.github/workflows/ci.yml
permissions:
contents: read
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.13"
- name: Check tag matches pyproject version
# A v0.9.1 tag on a pyproject still saying 0.9.0 would publish the
# wrong thing; fail fast instead.
run: |
TAG_VERSION="${GITHUB_REF_NAME#v}"
PYPROJECT_VERSION="$(python -c 'import tomllib; print(tomllib.load(open("pyproject.toml","rb"))["project"]["version"])')"
if [ "$TAG_VERSION" != "$PYPROJECT_VERSION" ]; then
echo "Tag $GITHUB_REF_NAME does not match pyproject.toml version $PYPROJECT_VERSION" >&2
exit 1
fi
- name: Build sdist and wheel
run: |
python -m pip install --upgrade pip build twine
python -m build
- name: Check package metadata
run: python -m twine check --strict dist/*
- name: Check the wheel carries the simulator package data
# Fonts + calibration JSONs are declared in [tool.setuptools.package-data];
# CI's editable install can't detect them going missing, so guard here.
run: |
python -m zipfile -l dist/*.whl | grep -q "simulator/fonts/tom-thumb.bdf"
python -m zipfile -l dist/*.whl | grep -q "simulator/core/matrixportal_s3_baseline.json"
- uses: actions/upload-artifact@v4
with:
name: dist
path: dist/
publish:
# Both gates, not just the build: the artifact can be perfectly well-formed
# and still be broken code. `build` runs alongside `ci` rather than after it,
# so the gate costs no extra wall-clock on a green release.
needs: [build, ci]
runs-on: ubuntu-latest
environment:
name: pypi
url: https://pypi.org/p/scrollkit
permissions:
id-token: write # required for PyPI Trusted Publishing (OIDC)
steps:
- uses: actions/download-artifact@v4
with:
name: dist
path: dist/
- name: Publish to PyPI
uses: pypa/gh-action-pypi-publish@release/v1