diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml new file mode 100644 index 0000000..5493fbb --- /dev/null +++ b/.github/workflows/publish.yml @@ -0,0 +1,104 @@ +# Build and publish jsonpointer to PyPI when a GitHub release is published. +# +# Uses PyPI Trusted Publishing (OIDC), so no API token is stored in GitHub. +# +# One-time setup: +# +# 1. On PyPI, open https://pypi.org/manage/project/jsonpointer/settings/publishing/ +# and add a GitHub trusted publisher with: +# Owner: stefankoegl +# Repository name: python-json-pointer +# Workflow name: publish.yml +# Environment name: pypi +# +# 2. In GitHub, go to Settings -> Environments -> New environment and create +# an environment named "pypi". Optionally add yourself as a required +# reviewer so every upload needs a manual approval, and restrict +# deployments to tags (e.g. "v*"). +# +# 3. (Optional) Repeat steps 1 and 2 on https://test.pypi.org with the +# environment name "testpypi" to enable test uploads via manual runs. +# +# Releasing: +# +# Bump __version__ in jsonpointer.py, commit, tag, push the tag, and publish +# a GitHub release for that tag. The workflow builds the sdist and wheel and +# uploads them to PyPI. Running the workflow manually ("Run workflow") uploads +# to TestPyPI instead. + +name: Publish to PyPI + +on: + release: + types: [published] + workflow_dispatch: + +jobs: + build: + name: Build distributions + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - uses: actions/checkout@v4 + + - name: Set up Python + uses: actions/setup-python@v5 + with: + python-version: "3.13" + + - name: Install build tools + run: | + python -m pip install --upgrade pip + pip install build twine + + - name: Build sdist and wheel + run: python -m build + + - name: Check distributions + run: twine check --strict dist/* + + - uses: actions/upload-artifact@v4 + with: + name: dist + path: dist/ + + publish-pypi: + name: Publish to PyPI + if: github.event_name == 'release' + needs: [build] + runs-on: ubuntu-latest + environment: + name: pypi + url: https://pypi.org/project/jsonpointer/ + permissions: + id-token: write + steps: + - uses: actions/download-artifact@v4 + with: + name: dist + path: dist/ + + - name: Publish to PyPI + uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 + + publish-testpypi: + name: Publish to TestPyPI + if: github.event_name == 'workflow_dispatch' + needs: [build] + runs-on: ubuntu-latest + environment: + name: testpypi + url: https://test.pypi.org/project/jsonpointer/ + permissions: + id-token: write + steps: + - uses: actions/download-artifact@v4 + with: + name: dist + path: dist/ + + - name: Publish to TestPyPI + uses: pypa/gh-action-pypi-publish@release/v1 + with: + repository-url: https://test.pypi.org/legacy/