--- name: Release on: workflow_dispatch: permissions: contents: read defaults: run: shell: bash -euo pipefail {0} working-directory: . jobs: build: permissions: contents: write id-token: write uses: dceoy/gh-actions-for-devops/.github/workflows/python-package-release-on-pypi-and-github.yml@main # zizmor: ignore[unpinned-uses] with: package-path: . create-releases: false secrets: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} github-release: name: Sign the Python 🐍 distribution 📦 with Sigstore and upload them to GitHub Release if: > startsWith(github.ref, 'refs/tags/') needs: - build runs-on: ubuntu-latest permissions: contents: write # IMPORTANT: mandatory for making GitHub Releases id-token: write # IMPORTANT: mandatory for sigstore steps: - name: Download all the dists uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: ${{ needs.build.outputs.distribution-artifact-name }} path: dist/ - name: Validate the version-tag consistency env: TAG_NAME: ${{ github.ref_name }} NEEDS_BUILD_OUTPUTS_PROJECT_NAME: ${{ needs.build.outputs.project-name }} run: | v="$( \ find dist -type f -name "${NEEDS_BUILD_OUTPUTS_PROJECT_NAME}-*" -exec basename {} \; \ | head -n 1 \ | cut -d '-' -f 2 \ )" v="${v%.tar.gz}" if [[ "${TAG_NAME}" != "${v}" ]] && [[ "${TAG_NAME}" != "v${v}" ]]; then echo "The tag (${TAG_NAME}) is inconsistent with the version (${v})." && exit 1 fi - name: Sign the dists with Sigstore uses: sigstore/gh-action-sigstore-python@04cffa1d795717b140764e8b640de88853c92acc # v3.3.0 with: inputs: >- ./dist/*.whl - name: Create GitHub Release env: REPOSITORY: ${{ github.repository }} GH_TOKEN: ${{ secrets.GH_TOKEN || secrets.GITHUB_TOKEN }} # zizmor: ignore[secrets-outside-env] caller-provided secret run: | gh release create "${GITHUB_REF_NAME}" --repo "${REPOSITORY}" --generate-notes --verify-tag - name: Upload artifact signatures to GitHub Release env: REPOSITORY: ${{ github.repository }} GH_TOKEN: ${{ secrets.GH_TOKEN || secrets.GITHUB_TOKEN }} # zizmor: ignore[secrets-outside-env] caller-provided secret # Upload to GitHub Release using the `gh` CLI. # `dist/` contains the built packages, and the # sigstore-produced signatures and certificates. run: | gh release upload "${GITHUB_REF_NAME}" dist/** --repo "${REPOSITORY}" publish-to-pypi: name: Publish the Python 🐍 distribution 📦 to PyPI if: > startsWith(github.ref, 'refs/tags/') needs: - build - github-release runs-on: ubuntu-latest environment: name: pypi url: https://pypi.org/p/${{ needs.build.outputs.project-name }} permissions: id-token: write # IMPORTANT: mandatory for trusted publishing steps: - name: Download all the dists uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: name: ${{ needs.build.outputs.distribution-artifact-name }} path: dist/ - name: Publish distribution 📦 to PyPI uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # v1.14.0 with: verbose: true