🌱 Commit e9e8680fa2a5c4982fc3b1bc76e070bd091b66ad triggered by: push of refs/heads/main branch (workflow run ID: 26662339381; number: 1; attempt: 1) #1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| --- | |
| name: 🧪 | |
| on: | |
| merge_group: | |
| push: # publishes to TestPyPI pushes to the main branch | |
| branches-ignore: | |
| - dependabot/** # Dependabot always creates PRs | |
| - gh-readonly-queue/** # Temporary merge queue-related GH-made branches | |
| - maintenance/pip-tools-constraint-lockfiles # Lock files through PRs | |
| - maintenance/pip-tools-constraint-lockfiles-** # Lock files through PRs | |
| - patchback/backports/** # Patchback always creates PRs | |
| - pre-commit-ci-update-config # pre-commit.ci always creates a PR | |
| pull_request: | |
| paths-ignore: # changes to the cron workflow are triggered through it | |
| - .github/workflows/scheduled-runs.yml | |
| types: | |
| - opened # default | |
| - synchronize # default | |
| - reopened # default | |
| - ready_for_review # used in PRs created from GitHub Actions workflows | |
| workflow_call: # a way to embed the main tests | |
| workflow_dispatch: | |
| inputs: | |
| release-version: | |
| # github.event_name == 'workflow_dispatch' | |
| # && github.event.inputs.release-version | |
| description: >- | |
| Target PEP440-compliant version to release. | |
| Please, don't prepend `v`. | |
| required: true | |
| type: string | |
| release-committish: | |
| # github.event_name == 'workflow_dispatch' | |
| # && github.event.inputs.release-committish | |
| default: '' | |
| description: >- | |
| The commit to be released to PyPI and tagged | |
| in Git as `release-version`. Normally, you | |
| should keep this empty. | |
| type: string | |
| YOLO: | |
| default: false | |
| description: >- | |
| Set this flag to disregard the outcome of the | |
| test stage. The test results will block the | |
| release otherwise. Only use this under | |
| extraordinary circumstances to ignore the test | |
| failures and cut the release regardless. | |
| type: boolean | |
| concurrency: | |
| group: >- | |
| ${{ | |
| github.workflow | |
| }}-${{ | |
| github.ref_type | |
| }}-${{ | |
| github.event.pull_request.number || github.sha | |
| }} | |
| cancel-in-progress: true | |
| env: | |
| FORCE_COLOR: 1 # Request colored output from CLI tools supporting it | |
| MYPY_FORCE_COLOR: 1 # MyPy's color enforcement | |
| PIP_DISABLE_PIP_VERSION_CHECK: 1 # Hide "there's a newer pip" message | |
| PIP_NO_PYTHON_VERSION_WARNING: 1 # Hide "this Python is deprecated" message | |
| PIP_NO_WARN_SCRIPT_LOCATION: 1 # Hide "script dir is not in $PATH" message | |
| PRE_COMMIT_COLOR: always | |
| PUBLISHING_TO_TESTPYPI_ENABLED: false | |
| PY_COLORS: 1 # Recognized by the `py` package, dependency of `pytest` | |
| PYTHONIOENCODING: utf-8 | |
| PYTHONUTF8: 1 | |
| TOX_PARALLEL_NO_SPINNER: 1 # Disable tox's parallel run spinner animation | |
| TOX_TESTENV_PASSENV: >- # Make tox-wrapped tools see color requests | |
| FORCE_COLOR | |
| MYPY_FORCE_COLOR | |
| NO_COLOR | |
| PIP_DISABLE_PIP_VERSION_CHECK | |
| PIP_NO_PYTHON_VERSION_WARNING | |
| PIP_NO_WARN_SCRIPT_LOCATION | |
| PRE_COMMIT_COLOR | |
| PY_COLORS | |
| PYTEST_THEME | |
| PYTEST_THEME_MODE | |
| PYTHONIOENCODING | |
| PYTHONLEGACYWINDOWSSTDIO | |
| PYTHONUTF8 | |
| UPSTREAM_REPOSITORY_ID: >- | |
| 1226310623 | |
| run-name: >- | |
| ${{ | |
| github.event_name == 'workflow_dispatch' | |
| && format('📦 Releasing v{0}...', github.event.inputs.release-version) | |
| || '' | |
| }} | |
| ${{ | |
| github.event.pull_request.number && '🔀 PR' || '' | |
| }}${{ | |
| !github.event.pull_request.number && '🌱 Commit' || '' | |
| }} | |
| ${{ github.event.pull_request.number || github.sha }} | |
| triggered by: ${{ github.event_name }} of ${{ | |
| github.ref | |
| }} ${{ | |
| github.ref_type | |
| }} | |
| (workflow run ID: ${{ | |
| github.run_id | |
| }}; number: ${{ | |
| github.run_number | |
| }}; attempt: ${{ | |
| github.run_attempt | |
| }}) | |
| jobs: | |
| pre-setup: | |
| name: ⚙️ Pre-set global build settings | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 3 # network is slow sometimes when fetching from Git | |
| defaults: | |
| run: | |
| shell: python | |
| outputs: | |
| # NOTE: These aren't env vars because the `${{ env }}` context is | |
| # NOTE: inaccessible when passing inputs to reusable workflows. | |
| dists-artifact-name: python-package-distributions | |
| dist-version: >- | |
| ${{ | |
| steps.request-check.outputs.release-requested == 'true' | |
| && github.event.inputs.release-version | |
| || steps.scm-version.outputs.dist-version | |
| }} | |
| is-untagged-devel: >- | |
| ${{ steps.untagged-check.outputs.is-untagged-devel || 'false' }} | |
| release-requested: >- | |
| ${{ | |
| steps.request-check.outputs.release-requested || 'false' | |
| }} | |
| is-yolo-mode: >- | |
| ${{ | |
| toJSON( | |
| steps.request-check.outputs.release-requested == 'true' | |
| && github.event.inputs.YOLO | |
| ) | |
| }} | |
| cache-key-for-dep-files: >- | |
| ${{ steps.calc-cache-key-files.outputs.cache-key-for-dep-files }} | |
| git-tag: ${{ steps.git-tag.outputs.tag }} | |
| project-name: ${{ steps.metadata.outputs.project-name }} | |
| sdist-artifact-name: ${{ steps.artifact-name.outputs.sdist }} | |
| wheel-artifact-name: ${{ steps.artifact-name.outputs.wheel }} | |
| is-upstream-repository: >- | |
| ${{ toJSON(env.UPSTREAM_REPOSITORY_ID == github.repository_id) }} | |
| publishing-to-testpypi-enabled: ${{ env.PUBLISHING_TO_TESTPYPI_ENABLED }} | |
| is-debug-mode: ${{ toJSON(runner.debug == '1') }} | |
| steps: | |
| - name: Switch to using Python 3.11 by default | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: 3.11 | |
| - name: >- | |
| Mark the build as untagged '${{ | |
| github.event.repository.default_branch | |
| }}' branch build | |
| id: untagged-check | |
| if: >- | |
| github.event_name == 'push' | |
| && github.ref_type == 'branch' | |
| && github.ref_name == github.event.repository.default_branch | |
| run: | | |
| from os import environ | |
| from pathlib import Path | |
| FILE_APPEND_MODE = 'a' | |
| with Path(environ['GITHUB_OUTPUT']).open( | |
| mode=FILE_APPEND_MODE, | |
| ) as outputs_file: | |
| print('is-untagged-devel=true', file=outputs_file) | |
| - name: Mark the build as "release request" | |
| id: request-check | |
| if: github.event_name == 'workflow_dispatch' | |
| run: | | |
| from os import environ | |
| from pathlib import Path | |
| FILE_APPEND_MODE = 'a' | |
| with Path(environ['GITHUB_OUTPUT']).open( | |
| mode=FILE_APPEND_MODE, | |
| ) as outputs_file: | |
| print('release-requested=true', file=outputs_file) | |
| - name: Check out src from Git | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: >- | |
| ${{ | |
| steps.request-check.outputs.release-requested == 'true' | |
| && 1 | |
| || 0 | |
| }} | |
| ref: ${{ github.event.inputs.release-committish }} | |
| - name: Scan static PEP 621 core packaging metadata | |
| id: metadata | |
| run: | | |
| from os import environ | |
| from pathlib import Path | |
| from tomllib import loads as parse_toml_from_string | |
| FILE_APPEND_MODE = 'a' | |
| pyproject_toml_txt = Path('pyproject.toml').read_text() | |
| metadata = parse_toml_from_string(pyproject_toml_txt)['project'] | |
| project_name = metadata["name"] | |
| with Path(environ['GITHUB_OUTPUT']).open( | |
| mode=FILE_APPEND_MODE, | |
| ) as outputs_file: | |
| print(f'project-name={project_name}', file=outputs_file) | |
| - name: >- | |
| Calculate dependency files' combined hash value | |
| for use in the cache key | |
| id: calc-cache-key-files | |
| uses: ./.github/actions/cache-keys | |
| - name: Set up pip cache | |
| if: >- | |
| steps.request-check.outputs.release-requested != 'true' | |
| uses: re-actors/cache-python-deps@release/v1 | |
| with: | |
| cache-key-for-dependency-files: >- | |
| ${{ steps.calc-cache-key-files.outputs.cache-key-for-dep-files }} | |
| - name: Drop Git tags from HEAD for non-release requests | |
| if: >- | |
| steps.request-check.outputs.release-requested != 'true' | |
| run: >- | |
| git tag --points-at HEAD | |
| | | |
| xargs git tag --delete | |
| shell: bash | |
| - name: Set up versioning prerequisites | |
| if: >- | |
| steps.request-check.outputs.release-requested != 'true' | |
| run: >- | |
| python -m | |
| pip install | |
| --user | |
| setuptools-scm | |
| shell: bash | |
| - name: Set the current dist version from Git | |
| if: steps.request-check.outputs.release-requested != 'true' | |
| id: scm-version | |
| run: | | |
| from os import environ | |
| from pathlib import Path | |
| import setuptools_scm | |
| FILE_APPEND_MODE = 'a' | |
| ver = setuptools_scm.get_version( | |
| ${{ | |
| steps.untagged-check.outputs.is-untagged-devel == 'true' | |
| && 'local_scheme="no-local-version"' || '' | |
| }} | |
| ) | |
| with Path(environ['GITHUB_OUTPUT']).open( | |
| mode=FILE_APPEND_MODE, | |
| ) as outputs_file: | |
| print(f'dist-version={ver}', file=outputs_file) | |
| print( | |
| f'dist-version-for-filenames={ver.replace("+", "-")}', | |
| file=outputs_file, | |
| ) | |
| - name: Set the target Git tag | |
| id: git-tag | |
| run: | | |
| from os import environ | |
| from pathlib import Path | |
| FILE_APPEND_MODE = 'a' | |
| with Path(environ['GITHUB_OUTPUT']).open( | |
| mode=FILE_APPEND_MODE, | |
| ) as outputs_file: | |
| print( | |
| "tag=v${{ | |
| steps.request-check.outputs.release-requested == 'true' | |
| && github.event.inputs.release-version | |
| || steps.scm-version.outputs.dist-version | |
| }}", | |
| file=outputs_file, | |
| ) | |
| - name: Set the expected dist artifact names | |
| id: artifact-name | |
| env: | |
| PROJECT_NAME: ${{ steps.metadata.outputs.project-name }} | |
| run: | | |
| from os import environ | |
| from pathlib import Path | |
| FILE_APPEND_MODE = 'a' | |
| whl_file_prj_base_name = environ['PROJECT_NAME'].replace('-', '_') | |
| sdist_file_prj_base_name = whl_file_prj_base_name.replace('.', '_') | |
| with Path(environ['GITHUB_OUTPUT']).open( | |
| mode=FILE_APPEND_MODE, | |
| ) as outputs_file: | |
| print( | |
| f"sdist={sdist_file_prj_base_name !s}-${{ | |
| steps.request-check.outputs.release-requested == 'true' | |
| && github.event.inputs.release-version | |
| || steps.scm-version.outputs.dist-version | |
| }}.tar.gz", | |
| file=outputs_file, | |
| ) | |
| print( | |
| f"wheel={whl_file_prj_base_name !s}-${{ | |
| steps.request-check.outputs.release-requested == 'true' | |
| && github.event.inputs.release-version | |
| || steps.scm-version.outputs.dist-version | |
| }}-py3-none-any.whl", | |
| file=outputs_file, | |
| ) | |
| build: | |
| name: >- | |
| 📦 ${{ needs.pre-setup.outputs.git-tag }} | |
| [mode: ${{ | |
| fromJSON(needs.pre-setup.outputs.is-untagged-devel) | |
| && 'nightly' || '' | |
| }}${{ | |
| fromJSON(needs.pre-setup.outputs.release-requested) | |
| && 'release' || '' | |
| }}${{ | |
| ( | |
| !fromJSON(needs.pre-setup.outputs.is-untagged-devel) | |
| && !fromJSON(needs.pre-setup.outputs.release-requested) | |
| ) && 'test' || '' | |
| }}] | |
| needs: | |
| - pre-setup | |
| uses: tox-dev/workflow/.github/workflows/reusable-tox.yml@cf231470741185d1bbb3ba45f9aa904b171c47dc # yamllint disable-line rule:line-length | |
| with: | |
| cache-key-for-dependency-files: >- | |
| ${{ needs.pre-setup.outputs.cache-key-for-dep-files }} | |
| check-name: Build dists under 🐍3.11 | |
| checkout-src-git-committish: >- | |
| ${{ github.event.inputs.release-committish }} | |
| checkout-src-git-fetch-depth: >- | |
| ${{ | |
| fromJSON(needs.pre-setup.outputs.release-requested) | |
| && 1 | |
| || 0 | |
| }} | |
| job-dependencies-context: >- # context for hooks | |
| ${{ toJSON(needs) }} | |
| python-version: 3.11 | |
| runner-vm-os: ubuntu-latest | |
| timeout-minutes: 3 # network is slow sometimes when fetching from Git | |
| toxenv: build-dists | |
| tox-tool-deps: tox | |
| xfail: false | |
| lint: | |
| name: 🧹 Linters${{ '' }} # nest jobs under the same sidebar category | |
| needs: | |
| - build | |
| - pre-setup # transitive, for accessing settings | |
| strategy: | |
| matrix: | |
| runner-vm-os: | |
| - ubuntu-latest | |
| python-version: | |
| - 3.11 | |
| toxenv: | |
| - pre-commit | |
| - metadata-validation | |
| xfail: | |
| - false | |
| fail-fast: false | |
| uses: tox-dev/workflow/.github/workflows/reusable-tox.yml@cf231470741185d1bbb3ba45f9aa904b171c47dc # yamllint disable-line rule:line-length | |
| with: | |
| built-wheel-names: >- | |
| ${{ | |
| matrix.toxenv == 'metadata-validation' | |
| && needs.pre-setup.outputs.wheel-artifact-name | |
| || '' | |
| }} | |
| cache-key-for-dependency-files: >- | |
| ${{ needs.pre-setup.outputs.cache-key-for-dep-files }} | |
| checkout-src-git-committish: >- | |
| ${{ github.event.inputs.release-committish }} | |
| checkout-src-git-fetch-depth: >- | |
| ${{ | |
| fromJSON(needs.pre-setup.outputs.release-requested) | |
| && 1 | |
| || 0 | |
| }} | |
| dists-artifact-name: >- | |
| ${{ needs.pre-setup.outputs.dists-artifact-name }} | |
| job-dependencies-context: >- # context for hooks | |
| ${{ toJSON(needs) }} | |
| post-toxenv-preparation-command: >- | |
| ${{ | |
| matrix.toxenv == 'pre-commit' | |
| && 'python -Im pre_commit install-hooks' | |
| || '' | |
| }} | |
| python-version: >- | |
| ${{ matrix.python-version }} | |
| require-successful-codecov-uploads: >- | |
| ${{ | |
| needs.pre-setup.outputs.is-upstream-repository | |
| }} | |
| runner-vm-os: >- | |
| ${{ matrix.runner-vm-os }} | |
| # NOTE: `pre-commit --show-diff-on-failure` depends on the presence of | |
| # NOTE: a Git repository. | |
| source-tarball-name: >- | |
| ${{ | |
| matrix.toxenv != 'pre-commit' | |
| && needs.pre-setup.outputs.sdist-artifact-name | |
| || '' | |
| }} | |
| # NOTE: `pre-commit` depends on Git, hence bigger timeout. | |
| timeout-minutes: >- | |
| ${{ | |
| matrix.toxenv == 'pre-commit' | |
| && 4 | |
| || 2 | |
| }} | |
| toxenv: >- | |
| ${{ matrix.toxenv }} | |
| tox-tool-deps: tox | |
| xfail: >- | |
| ${{ | |
| fromJSON(needs.pre-setup.outputs.is-yolo-mode) | |
| || matrix.xfail | |
| }} | |
| secrets: | |
| codecov-token: ${{ secrets.CODECOV_TOKEN }} | |
| tests: | |
| name: 🧪 Tests${{ '' }} # nest jobs under the same sidebar category | |
| needs: | |
| - build | |
| - pre-setup # transitive, for accessing settings | |
| strategy: | |
| fail-fast: >- # ${{ runner.debug }} is unavailable in this context | |
| ${{ | |
| fromJSON(needs.pre-setup.outputs.is-debug-mode) | |
| && false | |
| || true | |
| }} | |
| matrix: | |
| python-version: | |
| # NOTE: The latest and the lowest supported Pythons are prioritized | |
| # NOTE: to improve the responsiveness. It's nice to see the most | |
| # NOTE: important results first. | |
| - 3.14 | |
| - >- | |
| 3.10 | |
| - 3.11 | |
| - 3.12 | |
| - 3.13 | |
| - ~3.15.0-0 | |
| runner-vm-os: | |
| - ubuntu-24.04 | |
| - ubuntu-24.04-arm | |
| - macos-15 | |
| - macos-15-intel | |
| - windows-2025 | |
| - windows-11-arm | |
| toxenv: | |
| - py | |
| xfail: | |
| - false | |
| exclude: | |
| - python-version: >- # no Python 3.10 builds for windows-11-arm | |
| 3.10 | |
| runner-vm-os: windows-11-arm | |
| uses: tox-dev/workflow/.github/workflows/reusable-tox.yml@cf231470741185d1bbb3ba45f9aa904b171c47dc # yamllint disable-line rule:line-length | |
| with: | |
| built-wheel-names: >- | |
| ${{ needs.pre-setup.outputs.wheel-artifact-name }} | |
| cache-key-for-dependency-files: >- | |
| ${{ needs.pre-setup.outputs.cache-key-for-dep-files }} | |
| check-name: >- | |
| 🧪 🐍${{ | |
| matrix.python-version | |
| }} @ ${{ | |
| matrix.runner-vm-os | |
| }} | |
| dists-artifact-name: >- | |
| ${{ needs.pre-setup.outputs.dists-artifact-name }} | |
| job-dependencies-context: >- # context for hooks | |
| ${{ toJSON(needs) }} | |
| python-version: >- | |
| ${{ matrix.python-version }} | |
| require-successful-codecov-uploads: >- | |
| ${{ | |
| needs.pre-setup.outputs.is-upstream-repository | |
| }} | |
| runner-vm-os: >- | |
| ${{ matrix.runner-vm-os }} | |
| source-tarball-name: >- | |
| ${{ needs.pre-setup.outputs.sdist-artifact-name }} | |
| timeout-minutes: 5 | |
| toxenv: >- | |
| ${{ matrix.toxenv }} | |
| # tox-provision-args: >- | |
| # --force-dep '...' | |
| tox-run-posargs: >- | |
| --cov-report=xml:.tox/.tmp/.test-results/pytest-${{ | |
| matrix.python-version | |
| }}/cobertura.xml | |
| --junitxml=.tox/.tmp/.test-results/pytest-${{ | |
| matrix.python-version | |
| }}/test.xml | |
| tox-rerun-posargs: >- | |
| --no-cov | |
| -vvvvv | |
| --lf | |
| tox-tool-deps: tox | |
| xfail: >- | |
| ${{ | |
| fromJSON(needs.pre-setup.outputs.is-yolo-mode) | |
| || matrix.xfail | |
| }} | |
| secrets: | |
| codecov-token: ${{ secrets.CODECOV_TOKEN }} | |
| check: # This job does nothing and is only used for the branch protection | |
| if: always() | |
| needs: | |
| - lint | |
| - pre-setup # transitive, for accessing settings | |
| - tests | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 1 | |
| steps: | |
| - name: Decide whether the needed jobs succeeded or failed | |
| uses: re-actors/alls-green@release/v1 | |
| with: | |
| allowed-failures: >- | |
| ${{ | |
| fromJSON(needs.pre-setup.outputs.is-yolo-mode) | |
| && 'lint, tests' | |
| || '' | |
| }} | |
| jobs: ${{ toJSON(needs) }} | |
| notify-codecov: | |
| name: Coverage processing | |
| if: >- | |
| !cancelled() | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 1 | |
| needs: | |
| - pre-setup # transitive, for accessing settings | |
| - lint | |
| - tests | |
| steps: | |
| - name: Notify Codecov that all coverage reports have been uploaded | |
| if: >- | |
| !cancelled() | |
| # yamllint disable rule:line-length | |
| uses: codecov/codecov-action@57e3a136b779b570ffcdbf80b3bdc90e7fab3de2 # v6.0.0 | |
| # yamllint enable rule:line-length | |
| with: | |
| fail_ci_if_error: >- | |
| ${{ fromJSON(needs.pre-setup.outputs.is-upstream-repository) }} | |
| run_command: send-notifications | |
| publish-pypi: | |
| name: >- | |
| 📦 | |
| Publish ${{ needs.pre-setup.outputs.git-tag }} to PyPI | |
| needs: | |
| - check | |
| - pre-setup # transitive, for accessing settings | |
| if: >- | |
| always() | |
| && needs.check.result == 'success' | |
| && fromJSON(needs.pre-setup.outputs.release-requested) | |
| && fromJSON(needs.pre-setup.outputs.is-upstream-repository) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 2 # docker+network are slow sometimes | |
| environment: | |
| name: pypi | |
| url: >- | |
| https://pypi.org/project/${{ | |
| needs.pre-setup.outputs.project-name | |
| }}/${{ | |
| needs.pre-setup.outputs.dist-version | |
| }} | |
| permissions: | |
| contents: read # This job doesn't need to `git push` anything | |
| id-token: write # PyPI Trusted Publishing (OIDC) | |
| steps: | |
| - name: Download all the dists | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: >- | |
| ${{ needs.pre-setup.outputs.dists-artifact-name }} | |
| path: dist/ | |
| - name: >- | |
| 📦 | |
| Publish ${{ needs.pre-setup.outputs.git-tag }} to PyPI | |
| 🔏 | |
| uses: pypa/gh-action-pypi-publish@release/v1 | |
| publish-testpypi: | |
| name: >- | |
| 📦 | |
| Publish ${{ needs.pre-setup.outputs.git-tag }} to TestPyPI | |
| needs: | |
| - check | |
| - pre-setup # transitive, for accessing settings | |
| if: >- | |
| always() | |
| && needs.check.result == 'success' | |
| && ( | |
| fromJSON(needs.pre-setup.outputs.is-untagged-devel) | |
| || fromJSON(needs.pre-setup.outputs.release-requested) | |
| ) | |
| && fromJSON(needs.pre-setup.outputs.is-upstream-repository) | |
| && fromJSON(needs.pre-setup.outputs.publishing-to-testpypi-enabled) | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 2 # docker+network are slow sometimes | |
| environment: | |
| name: testpypi | |
| url: >- | |
| https://test.pypi.org/project/${{ | |
| needs.pre-setup.outputs.project-name | |
| }}/${{ | |
| needs.pre-setup.outputs.dist-version | |
| }} | |
| permissions: | |
| contents: read # This job doesn't need to `git push` anything | |
| id-token: write # PyPI Trusted Publishing (OIDC) | |
| steps: | |
| - name: Download all the dists | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: >- | |
| ${{ needs.pre-setup.outputs.dists-artifact-name }} | |
| path: dist/ | |
| - name: >- | |
| 📦 | |
| Publish ${{ needs.pre-setup.outputs.git-tag }} to TestPyPI | |
| 🔏 | |
| uses: pypa/gh-action-pypi-publish@release/v1 | |
| with: | |
| repository-url: https://test.pypi.org/legacy/ | |
| post-release-repo-update: | |
| name: >- | |
| 🏷️ | |
| Publish post-release Git tag | |
| for ${{ needs.pre-setup.outputs.git-tag }} | |
| needs: | |
| - publish-pypi | |
| - pre-setup # transitive, for accessing settings | |
| if: >- | |
| always() | |
| && needs.publish-pypi.result == 'success' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 1 | |
| permissions: | |
| contents: write # Mandatory for `git push` to work | |
| pull-requests: write | |
| steps: | |
| - name: Fetch the src snapshot # IMPORTANT: Must be before the tag check | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 2 | |
| ref: ${{ github.event.inputs.release-committish }} | |
| - name: >- | |
| Check if the requested tag ${{ needs.pre-setup.outputs.git-tag }} | |
| is present and is pointing at the required commit ${{ | |
| github.event.inputs.release-committish | |
| }} | |
| id: existing-remote-tag-check | |
| run: | | |
| set -eEuo pipefail | |
| REMOTE_TAGGED_COMMIT_SHA="$( | |
| git ls-remote --tags --refs "$(git remote get-url origin)" '${{ | |
| needs.pre-setup.outputs.git-tag | |
| }}' | awk '{print $1}' | |
| )" | |
| if [[ "${REMOTE_TAGGED_COMMIT_SHA}" == '' ]] | |
| then | |
| LAST_HUMAN_COMMIT_SHA= | |
| else | |
| LAST_HUMAN_COMMIT_SHA=$(git rev-parse "${REMOTE_TAGGED_COMMIT_SHA}"^) | |
| fi | |
| RELEASE_REQUEST_COMMIT_SHA=$(git rev-parse '${{ | |
| github.event.inputs.release-committish || 'HEAD' | |
| }}') | |
| if [[ "${LAST_HUMAN_COMMIT_SHA}" == "${RELEASE_REQUEST_COMMIT_SHA}" ]] | |
| then | |
| echo "already-exists=true" >> "${GITHUB_OUTPUT}" | |
| fi | |
| - name: Setup git user as [bot] | |
| if: steps.existing-remote-tag-check.outputs.already-exists != 'true' | |
| # Refs: | |
| # * https://github.qkg1.topmunity/t/github-actions-bot-email-address/17204/6 | |
| # * https://github.com/actions/checkout/issues/13#issuecomment-724415212 | |
| uses: fregante/setup-git-user@v2 | |
| - name: >- | |
| 🏷️ | |
| Tag the release in the local Git repo | |
| as ${{ needs.pre-setup.outputs.git-tag }} | |
| if: steps.existing-remote-tag-check.outputs.already-exists != 'true' | |
| run: >- | |
| git tag | |
| -m '${{ needs.pre-setup.outputs.git-tag }}' | |
| -m 'Published at https://pypi.org/project/${{ | |
| needs.pre-setup.outputs.project-name | |
| }}/${{ | |
| needs.pre-setup.outputs.dist-version | |
| }}' | |
| -m 'This release has been produced by the following workflow run: ${{ | |
| github.server_url | |
| }}/${{ | |
| github.repository | |
| }}/actions/runs/${{ | |
| github.run_id | |
| }}' | |
| '${{ needs.pre-setup.outputs.git-tag }}' | |
| -- | |
| ${{ github.event.inputs.release-committish }} | |
| - name: >- | |
| 🏷️ | |
| Push ${{ needs.pre-setup.outputs.git-tag }} tag corresponding | |
| to the just published release back to GitHub | |
| if: steps.existing-remote-tag-check.outputs.already-exists != 'true' | |
| run: >- | |
| git push --atomic origin | |
| '${{ needs.pre-setup.outputs.git-tag }}' | |
| slsa-provenance: | |
| name: >- | |
| 🔏 | |
| Save in-toto SLSA provenance as a GitHub workflow artifact for | |
| ${{ needs.pre-setup.outputs.git-tag }} | |
| needs: | |
| - build | |
| - post-release-repo-update | |
| - pre-setup # transitive, for accessing settings | |
| if: >- | |
| always() | |
| && needs.post-release-repo-update.result == 'success' | |
| permissions: | |
| actions: read | |
| id-token: write | |
| contents: write | |
| # Can't pin with hash due to how this workflow works. | |
| uses: slsa-framework/slsa-github-generator/.github/workflows/generator_generic_slsa3.yml@v2.0.0 # yamllint disable-line rule:line-length | |
| with: | |
| base64-subjects: >- | |
| ${{ | |
| fromJSON( | |
| needs.build.outputs.steps | |
| ).tox-run.outputs.combined-dists-base64-encoded-sha256-hash | |
| }} | |
| publish-github-attestations: | |
| name: >- | |
| 🔏 | |
| Produce a GitHub-native Attestations for | |
| ${{ needs.pre-setup.outputs.git-tag }} | |
| needs: | |
| - post-release-repo-update | |
| - pre-setup # transitive, for accessing settings | |
| if: >- | |
| always() | |
| && needs.post-release-repo-update.result == 'success' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 3 | |
| permissions: | |
| attestations: write # IMPORTANT: needed to persist attestations | |
| contents: read | |
| id-token: write # IMPORTANT: mandatory for Sigstore signing | |
| steps: | |
| - name: Download all the dists | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: >- | |
| ${{ needs.pre-setup.outputs.dists-artifact-name }} | |
| path: dist/ | |
| - name: >- | |
| 🔏 | |
| Generate provenance attestations for the dists | |
| uses: actions/attest-build-provenance@v1 | |
| with: | |
| subject-path: | | |
| dist/${{ needs.pre-setup.outputs.sdist-artifact-name }} | |
| dist/${{ needs.pre-setup.outputs.wheel-artifact-name }} | |
| publish-github-release: | |
| name: >- | |
| 🏷️ | |
| Publish a GitHub Release for | |
| ${{ needs.pre-setup.outputs.git-tag }} | |
| needs: | |
| - post-release-repo-update | |
| - pre-setup # transitive, for accessing settings | |
| - publish-github-attestations | |
| - slsa-provenance | |
| if: >- | |
| always() | |
| && needs.post-release-repo-update.result == 'success' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 3 | |
| permissions: | |
| contents: write | |
| discussions: write | |
| id-token: write # IMPORTANT: mandatory for Sigstore signing | |
| steps: | |
| - name: Download all the dists | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: >- | |
| ${{ needs.pre-setup.outputs.dists-artifact-name }} | |
| path: dist/ | |
| - name: Download SLSA provenance in-toto files | |
| uses: actions/download-artifact@v4 | |
| with: | |
| name: >- | |
| ${{ needs.slsa-provenance.outputs.provenance-name }} | |
| path: >- | |
| ${{ needs.slsa-provenance.outputs.provenance-name }} | |
| - name: Figure out if the current version is a pre-release | |
| id: release-maturity-check | |
| run: | | |
| from os import environ | |
| from pathlib import Path | |
| release_version = '${{ | |
| needs.pre-setup.outputs.dist-version | |
| }}' | |
| FILE_APPEND_MODE = 'a' | |
| is_pre_release = any( | |
| hint_char in release_version | |
| for hint_char in {'a', 'b', 'd', 'r'} | |
| ) | |
| with Path(environ['GITHUB_OUTPUT']).open( | |
| mode=FILE_APPEND_MODE, | |
| ) as outputs_file: | |
| print( | |
| f'is-pre-release={is_pre_release !s}'.lower(), | |
| file=outputs_file, | |
| ) | |
| shell: python | |
| - name: Prepare the release notes file for the GitHub Releases | |
| run: | | |
| echo '## 📝 Release notes' | tee -a release-notes.md | |
| echo | tee -a release-notes.md | |
| echo | tee -a release-notes.md | |
| echo '📦 PyPI page: https://pypi.org/project/${{ | |
| needs.pre-setup.outputs.project-name | |
| }}/${{ | |
| needs.pre-setup.outputs.dist-version | |
| }}' | tee -a release-notes.md | |
| echo | tee -a release-notes.md | |
| echo | tee -a release-notes.md | |
| echo '${{ | |
| steps.release-maturity-check.outputs.is-pre-release == 'true' | |
| && format( | |
| '🚧 {0} is marked as a pre-release.', | |
| needs.pre-setup.outputs.git-tag | |
| ) | |
| || format( | |
| '🌱 {0} is marked as a stable release.', | |
| needs.pre-setup.outputs.git-tag | |
| ) | |
| }}' | tee -a release-notes.md | |
| echo | tee -a release-notes.md | |
| echo | tee -a release-notes.md | |
| echo '🔗 This release has been produced by ' \ | |
| 'the following workflow run: ${{ | |
| github.server_url | |
| }}/${{ | |
| github.repository | |
| }}/actions/runs/${{ | |
| github.run_id | |
| }}' | tee -a release-notes.md | |
| echo | tee -a release-notes.md | |
| echo | tee -a release-notes.md | |
| shell: bash | |
| - name: Sign the dists with Sigstore | |
| uses: sigstore/gh-action-sigstore-python@v3.0.0 | |
| with: | |
| inputs: >- | |
| dist/${{ needs.pre-setup.outputs.sdist-artifact-name }} | |
| dist/${{ needs.pre-setup.outputs.wheel-artifact-name }} | |
| - name: >- | |
| Publish a GitHub Release for | |
| ${{ needs.pre-setup.outputs.git-tag }} | |
| with Sigstore-signed artifacts | |
| uses: ncipollo/release-action@v1 | |
| with: | |
| allowUpdates: false | |
| artifactErrorsFailBuild: false | |
| artifacts: | | |
| dist/${{ needs.pre-setup.outputs.sdist-artifact-name }} | |
| dist/${{ needs.pre-setup.outputs.sdist-artifact-name }}.sigstore.json | |
| dist/${{ needs.pre-setup.outputs.wheel-artifact-name }} | |
| dist/${{ needs.pre-setup.outputs.wheel-artifact-name }}.sigstore.json | |
| ${{ needs.slsa-provenance.outputs.provenance-name }}/* | |
| artifactContentType: raw # Because whl and tgz are of different types | |
| bodyFile: release-notes.md | |
| discussionCategory: Announcements | |
| draft: false | |
| name: ${{ needs.pre-setup.outputs.git-tag }} | |
| omitBodyDuringUpdate: true | |
| omitName: false | |
| omitNameDuringUpdate: true | |
| omitPrereleaseDuringUpdate: true | |
| prerelease: ${{ steps.release-maturity-check.outputs.is-pre-release }} | |
| removeArtifacts: false | |
| replacesArtifacts: false | |
| tag: ${{ needs.pre-setup.outputs.git-tag }} | |
| token: ${{ secrets.GITHUB_TOKEN }} | |
| ... |