Skip to content

Add GitHub Actions workflow for PyPI publishing - #85

Merged
stefankoegl merged 2 commits into
masterfrom
claude/determined-feynman-lzwpbs
Oct 7, 2026
Merged

stefankoegl merged 2 commits into
masterfrom
claude/determined-feynman-lzwpbs

Conversation

@stefankoegl

Copy link
Copy Markdown
Owner

Summary

This PR adds a GitHub Actions workflow to automate building and publishing the jsonpointer package to PyPI using trusted publishing (OIDC).

Key Changes

  • Added .github/workflows/publish.yml workflow that:
    • Builds source distribution (sdist) and wheel on every release
    • Publishes to PyPI automatically when a GitHub release is published
    • Supports manual test uploads to TestPyPI via workflow dispatch
    • Uses PyPI Trusted Publishing (OIDC) for secure, token-free authentication
    • Validates distributions with twine check before publishing

Implementation Details

  • The workflow is triggered on GitHub release publication or manual workflow dispatch
  • Build job runs on Ubuntu with Python 3.13 and uses the build and twine tools
  • Separate publish jobs for PyPI (automatic on release) and TestPyPI (manual only)
  • Uses pypa/gh-action-pypi-publish for secure OIDC-based publishing
  • Includes comprehensive setup instructions in comments for configuring trusted publishers on PyPI and GitHub environments
  • Artifacts are uploaded between jobs for efficient distribution handling

https://claude.ai/code/session_0148CNP2NjzB39ybyGyUcuWW

Builds sdist and wheel and uploads them to PyPI via Trusted Publishing
when a GitHub release is published. Manual runs upload to TestPyPI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0148CNP2NjzB39ybyGyUcuWW

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

OIDC-enabled publishing actions use mutable references that should be pinned to reviewed commit SHAs.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Adds automated OIDC-based publishing of jsonpointer distributions to PyPI and TestPyPI.

Changes:

  • Builds and validates wheel and source distributions.
  • Publishes releases to PyPI and manual runs to TestPyPI.
  • Transfers distributions between isolated build and publishing jobs.
File Description
.github/​workflows/​publish.yml Defines the build, validation, and trusted-publishing workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/publish.yml Outdated
…wed commit SHA'

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The TestPyPI publishing action uses a mutable reference while holding OIDC publishing permission.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@stefankoegl
stefankoegl merged commit a2af5bc into master Oct 7, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants