Skip to content

ci: publish to PyPI via Trusted Publishing (OIDC) #46

Description

@JoseVelazcoH

Problem

There is no automated publish to PyPI. release-please.yml creates the GitHub release + tag, but nothing uploads the package, so pip install erdalchemy does not get new versions (e.g. 0.5.0) without a manual python -m build + twine upload.

Proposed

Add .github/workflows/publish.yml that publishes to PyPI using Trusted Publishing (OIDC) — no API tokens stored in the repo:

  • Trigger on release: published (the event release-please emits when its release PR is merged).
  • permissions: id-token: write for OIDC.
  • Build with python -m build, validate with twine check, upload with pypa/gh-action-pypi-publish.

One-time setup (maintainer, on PyPI)

  • Configure a Trusted Publisher for the erdalchemy project pointing at this repo + workflow (or a pending publisher for the first publish if the project does not exist yet).

Notes

  • The default GITHUB_TOKEN does not chain-trigger workflows; using release: published from release-please's release is fine because the publish workflow keys off the release event, but verify it fires (may need a PAT or workflow_dispatch fallback).
  • Consider a TestPyPI dry-run job first.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions