audit-labs/audit-report

Turn audit-tools evidence packages into control-mapped, auditor-ready reports. audit compliance evidence reporting https://audit-labs.dev/audit-report/

Commit 46378648bc

46378648bcd1e39371d26e8ec4f4825b412fbafb

parent: 62f8ab416b

Verified · cmc

cmc <hello@cleberg.net> · 2026-08-25 19:07 UTC

publish to PyPI from gitbay CI on version tags

Layout: unified · split

.gitbay/ci.yml added +15
@@ -0,0 +1,15 @@
1# Tag-triggered PyPI publish, ported from the GitHub workflow (which used
2# OIDC trusted publishing; here twine authenticates with the PYPI_TOKEN
3# build secret).
4jobs:
5 publish:
6 tags: "v*"
7 steps:
8 - |
9 set -e
10 [ -n "$PYPI_TOKEN" ] || { echo "PYPI_TOKEN secret not set: printf %s TOKEN | gitbay repo secret set <repo> PYPI_TOKEN"; exit 1; }
11 python3 -m venv .venv
12 .venv/bin/pip install -q build twine
13 .venv/bin/python -m build
14 .venv/bin/twine check dist/*
15 TWINE_USERNAME=__token__ TWINE_PASSWORD="$PYPI_TOKEN" .venv/bin/twine upload --non-interactive dist/*
.github/workflows/release.yml deleted −36
@@ -1,36 +0,0 @@
1name: Release
2
3on:
4 push:
5 tags:
6 - "v*"
7
8jobs:
9 build:
10 runs-on: ubuntu-latest
11 steps:
12 - uses: actions/checkout@v5
13 - name: Install uv
14 uses: astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6
15 - name: Build
16 run: uv build
17 - name: Check
18 run: uvx twine@7.0.0 check dist/*
19 - uses: actions/upload-artifact@v4
20 with:
21 name: dist
22 path: dist/
23
24 publish:
25 needs: build
26 runs-on: ubuntu-latest
27 environment: pypi
28 permissions:
29 id-token: write
30 steps:
31 - uses: actions/download-artifact@v4
32 with:
33 name: dist
34 path: dist/
35 - name: Publish to PyPI
36 uses: pypa/gh-action-pypi-publish@release/v1