Skip to content

Commit b6ddf0c

Browse files
fix(publish): switch to OIDC trusted publisher (pypa/gh-action-pypi-publish), removes PYPI_API_TOKEN dependency
1 parent 31d5504 commit b6ddf0c

1 file changed

Lines changed: 15 additions & 19 deletions

File tree

‎.github/workflows/publish.yml‎

Lines changed: 15 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -7,17 +7,17 @@ on:
77
inputs:
88
pypi_target:
99
description: 'PyPI target (pypi or testpypi)'
10-
default: 'testpypi'
10+
default: 'pypi'
1111
type: choice
1212
options:
1313
- pypi
1414
- testpypi
1515

1616
jobs:
17-
build-and-publish:
17+
publish:
1818
runs-on: ubuntu-latest
19+
environment: pypi
1920
permissions:
20-
contents: read
2121
id-token: write
2222

2323
steps:
@@ -26,29 +26,25 @@ jobs:
2626
- name: Set up Python 3.11
2727
uses: actions/setup-python@v6
2828
with:
29-
python-version: "3.11"
29+
python-version: "3.12"
3030

31-
- name: Install build deps
31+
- name: Install dependencies
3232
run: |
33+
python -m pip install --upgrade pip
3334
pip install build twine
3435
3536
- name: Build package
36-
run: |
37-
python -m build
37+
run: python -m build
3838

39-
- name: Publish to PyPI
40-
if: ${{ inputs.pypi_target != 'testpypi' || github.event_name == 'release' }}
41-
env:
42-
TWINE_USERNAME: __token__
43-
TWINE_PASSWORD: ${{ secrets.PYPI_API_TOKEN }}
44-
run: |
45-
twine upload dist/* --verbose
39+
- name: Check package
40+
run: twine check dist/*
4641

4742
- name: Publish to TestPyPI
4843
if: ${{ inputs.pypi_target == 'testpypi' }}
49-
env:
50-
TWINE_USERNAME: __token__
51-
TWINE_PASSWORD: ${{ secrets.TEST_PYPI_API_TOKEN }}
52-
run: |
53-
twine upload --repository testpypi dist/* --verbose
44+
uses: pypa/gh-action-pypi-publish@release/v1
45+
with:
46+
repository-url: https://test.pypi.org/legacy/
5447

48+
- name: Publish to PyPI
49+
if: ${{ inputs.pypi_target == 'pypi' || github.event_name == 'release' }}
50+
uses: pypa/gh-action-pypi-publish@release/v1

0 commit comments

Comments
 (0)