Commit b57a7a0581
Verified · cmc
Layout: unified · split
.gitbay/ci.yml added +15
| @@ -0,0 +1,15 @@ | |||
| 1 | # Tag-triggered PyPI publish, ported from the GitHub workflow (which used | ||
| 2 | # OIDC trusted publishing; here twine authenticates with the PYPI_TOKEN | ||
| 3 | # build secret). | ||
| 4 | jobs: | ||
| 5 | publish: | ||
| 6 | tags: "v*" | ||
| 7 | steps: | ||
| 8 | - | | ||
| 9 | set -e | ||
| 10 | [ -n "$PYPI_TOKEN" ] || { echo "PYPI_TOKEN secret not set: printf %s TOKEN | gitbay repo secret set <repo> PYPI_TOKEN"; exit 1; } | ||
| 11 | python3 -m venv .venv | ||
| 12 | .venv/bin/pip install -q build twine | ||
| 13 | .venv/bin/python -m build | ||
| 14 | .venv/bin/twine check dist/* | ||
| 15 | TWINE_USERNAME=__token__ TWINE_PASSWORD="$PYPI_TOKEN" .venv/bin/twine upload --non-interactive dist/* | ||
.github/workflows/release.yml deleted −36
| @@ -1,36 +0,0 @@ | |||
| 1 | name: Release | ||
| 2 | |||
| 3 | on: | ||
| 4 | push: | ||
| 5 | tags: | ||
| 6 | - "v*" | ||
| 7 | |||
| 8 | jobs: | ||
| 9 | build: | ||
| 10 | runs-on: ubuntu-latest | ||
| 11 | steps: | ||
| 12 | - uses: actions/checkout@v5 | ||
| 13 | - name: Install uv | ||
| 14 | uses: astral-sh/setup-uv@d0cc045d04ccac9d8b7881df0226f9e82c39688e # v6 | ||
| 15 | - name: Build | ||
| 16 | run: uv build | ||
| 17 | - name: Check | ||
| 18 | run: uvx twine check dist/* | ||
| 19 | - uses: actions/upload-artifact@v4 | ||
| 20 | with: | ||
| 21 | name: dist | ||
| 22 | path: dist/ | ||
| 23 | |||
| 24 | publish: | ||
| 25 | needs: build | ||
| 26 | runs-on: ubuntu-latest | ||
| 27 | environment: pypi | ||
| 28 | permissions: | ||
| 29 | id-token: write | ||
| 30 | steps: | ||
| 31 | - uses: actions/download-artifact@v4 | ||
| 32 | with: | ||
| 33 | name: dist | ||
| 34 | path: dist/ | ||
| 35 | - name: Publish to PyPI | ||
| 36 | uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 | ||