Skip to content

Commit af260f5

Browse files
authored
fix(ci): inline the PyPI publish step instead of a composite action (#104)
* fix(ci): inline the PyPI publish step instead of a composite action pypa/gh-action-pypi-publish is a Docker container action. Nested inside reqstool/.github's actions/publish-to-pypi composite action, GitHub resolved its image using the composite action's own repo and pinned ref instead of the Docker action's, and every real publish failed with `docker: invalid reference format`. The action's own maintainers say this usage is untested and unsupported. Both steps -- download-artifact and the actual publish -- are now inline, matching the pattern the upstream workaround comment already showed (see reqstool/.github#95 for the full writeup). There is no shared action for this step in the org at all now; what remained after removing the publish call wasn't enough to justify one. Needs reqstool/.github#94 merged first. Signed-off-by: Jimisola Laursen <jimisola@jimisola.com> * refactor(ci): use download-dists for the artifact half Reworks the previous commit. Composite actions were not the problem -- one creates no new workflow context, so the job keeps this repo's own OIDC identity, which is why it works where a reusable workflow does not. Only pypa/gh-action-pypi-publish had to come out of it, because nesting a Docker container action makes GitHub resolve its image against the wrapping action's repository. So the download goes back to a shared action, renamed download-dists now that it no longer publishes, and only the publish step stays inline. Still pinned at @main here; reqstool/.github#94 has to merge before a commit SHA exists to pin to. That pin lands before this PR merges. Signed-off-by: Jimisola Laursen <jimisola@jimisola.com> --------- Signed-off-by: Jimisola Laursen <jimisola@jimisola.com>
1 parent a39c450 commit af260f5

1 file changed

Lines changed: 7 additions & 1 deletion

File tree

.github/workflows/release.yml

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -109,9 +109,15 @@ jobs:
109109
permissions:
110110
id-token: write
111111
steps:
112-
- uses: reqstool/.github/.github/actions/publish-to-pypi@b10b898cd5a1d552a578dbe4f170f84fb8f98b6c # main 2026-08-23
112+
- uses: reqstool/.github/.github/actions/download-dists@main
113113
with:
114114
artifact: dist-tagged
115+
# Inline, not inside download-dists: nesting this Docker action in a
116+
# composite action makes GitHub resolve its image against the wrapper's
117+
# repo. See reqstool/.github#95.
118+
- uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2
119+
with:
120+
attestations: true
115121

116122
# Last, deliberately. Everything above can fail, and until this runs nothing
117123
# resolving "the latest release" can see what was built -- the release is still

0 commit comments

Comments
 (0)