Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 40 additions & 0 deletions .github/workflows/publish-python.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
name: Publish to PyPI

on:
push:
tags:
- "python-v*"
workflow_dispatch:

permissions:
contents: read
id-token: write

jobs:
build-and-publish:
name: Build and publish to PyPI
runs-on: ubuntu-latest
environment: pypi

steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.11"

- name: Install build tools
run: pip install build twine

- name: Build package
run: python -m build

- name: Check distribution
run: twine check dist/*

- name: Publish to PyPI
# Pinned to a commit SHA, not a branch/tag ref — see python-sdk#10 for
# why: this job holds id-token: write in the pypi environment, i.e.
# authority to publish to PyPI as us, and a mutable ref could resolve
# to different code than what was reviewed.
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2
7 changes: 7 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,13 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0

## [Unreleased]

### Added
- CI workflow to publish `miniwdl-spawn` to PyPI on a `python-vX.Y.Z` tag, via
PyPI Trusted Publishing (OIDC, no stored API token) in a dedicated `pypi`
GitHub environment — the same mechanism `python-sdk` already uses. The
existing `vX.Y.Z`-triggered `release.yml` (GitHub Release only) is
unchanged; a PyPI publish is now a separate, deliberate tag.

### Changed
- CI moved off the self-hosted orion runner fleet onto `ubuntu-latest`. The
fleet (colima/Docker on orion.local) is being decommissioned org-wide; no
Expand Down
Loading