fix(release): release from master only, split jobs, ship LICENSE - #272
Merged
Merged
Conversation
…ish jobs release.yml could be dispatched on any branch, pushing the release commit there and publishing unmerged code, and the job that ran every dev dependency also held contents: write and id-token: write. Refuse a non-dry-run dispatch off master. Split the workflow into a build job (gate, bump, changelog, uv build; read-only, no persisted git credentials), a release job (commit, tag, GitHub release; contents: write, installs nothing) and a publish job (the only id-token: write, in the pypi environment). The later jobs download the build artifact instead of rebuilding. Ship LICENSE in the wheel and sdist via license-files, and add the Typing :: Typed classifier. Closes #231 Closes #232
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #231, closes #232.
#231 — release.yml
refs/heads/masterfails at the first step. Thereleaseandpublishjobs check the ref again in their job-levelif:. The release commit is pushed toHEAD:refs/heads/masterexplicitly instead of$BRANCH.build: runs the gate, the version bump, the tag check, the changelog promotion anduv build. It hascontents: read, and checks out withpersist-credentials: false, so the dev dependencies run with no write token and no PyPI token. It uploads one artifact,release-v<version>, containing the bumpedpyproject.toml,uv.lock,CHANGELOG.md,release-notes.mdanddist/. The same artifact is the dry-run output, replacingdry-run-v<version>.release(needs: build,contents: write): installs nothing. It checks out the samegithub.sha, downloads the artifact, then commits, pushes, tags and creates the GitHub release. If master has moved since the dispatch, the push is rejected as non-fast-forward before anything is tagged, same as before.publish(needs: [build, release],environment: pypi, the onlyid-token: write): downloadsdist/and runspypa/gh-action-pypi-publish, then writes the summary.contents: readonly.docs/DEVELOPMENT.md"Releasing" and "Rehearsing a release" describe the jobs and the master-only rule.Not done: pinning third-party actions by digest. The issue marks it optional, and Renovate would need configuring for it.
#232 — LICENSE
license-files = ["LICENSE"].Typing :: Typedclassifier.For the maintainer (repo/PyPI settings, not changed here)
pypienvironment: GitHub creates it on the first run that references it. Add protection rules (required reviewer, branch restriction tomaster) if you want them.pypities publishing to this job.dry_rundispatch on this branch will exercise thebuildjob, including the new artifact upload. Therelease/publishjobs only run for a real release.Verification
uv buildinto a temp dir, before and after:fastapi_cachex-0.3.7.dist-info/licenses/LICENSE, METADATA hasLicense-File: LICENSEandClassifier: Typing :: Typed, and the sdist containsfastapi_cachex-0.3.7/LICENSE.actionlint(with shellcheck) on.github/workflows/release.ymlonly: clean.pre-commit run --all-files: passed.uv run pytest -qwithout live servers: 800 passed, 190 skipped.zensical build --strict(English docs): clean.CHANGELOG
Under Security:
Under Fixed: