Skip to content

Upload to production PyPI from this workflow (needs .github#53 and a new publishing tag first) - #151

Merged
bdbarnett merged 3 commits into
mainfrom
caller-side-pypi-publish
Sep 27, 2026
Merged

bdbarnett merged 3 commits into
mainfrom
caller-side-pypi-publish

Conversation

@bdbarnett

Copy link
Copy Markdown
Contributor

Don't merge this until .github#53 is merged and a new publishing tag exists. Both reusable refs here say publishing-vNEXT, a placeholder. As written, the publish workflow fails at startup.

v0.6.1 failed at PyPI with invalid-publisher (run 36131566669). The upload ran inside PyDevices/.github's reusable workflow, and PyPI matches the Trusted Publisher against the workflow that runs the upload job, so it could never match publish-release-packages.yml here. The PyPI side is set up right. .github#53 has the full story.

This PR moves the upload into this file:

  • pypi runs when the coordinator's pypi-publish output is true. It downloads the coordinator's dist-artifact and uploads with Trusted Publishing, through the pypi environment (your approval, v* tags only). id-token: write is granted to this one job now, not to the whole workflow.
  • report-pypi sends the PyPI result to Release Health. The coordinator's report now says pending for PyPI, and this fills it in.

docs/building-wheels.md said 21 wheels and publishing-v8. It's 18, and the pin is now described where it lives.

Order

  1. Merge .github#53.
  2. In dotgithub, run scripts/cut_publishing_tag.sh 12 (or the next free number).
  3. Here, replace both publishing-vNEXT refs with that tag, delete the two placeholder comments, and merge.

The next final audiodsp release is the first to go through. v0.6.1 can't be retried this way: the pypi environment only deploys from v* tags, and a dispatch on v0.6.1 runs this file as it was at that tag. Either wait for the next release, or twine upload v0.6.1's Release assets by hand, the way 0.6.0 was parked.

Moving from v8 to the new tag also brings cibuildwheel 4.2.1 and setup-java v6 to the builds. Nothing else in audiodsp's path changes.

Checked

actionlint 1.7.12 is clean. I also linted this file against .github#53's reusables resolved locally, which checks every output and input name, and a planted misspelling of dist-artifact was caught. scripts/check_attribution.py passes. Nothing ran on GitHub.

v0.6.1's PyPI upload failed with invalid-publisher: PyPI matches the Trusted
Publisher against the workflow that runs the upload job, and that job ran
inside PyDevices/.github's reusable coordinator. The upload is now the pypi
job here, fed by the coordinator's pypi-publish and dist-artifact outputs, and
report-pypi tells Release Health how it went. id-token:write is granted to
that one job instead of the whole workflow.

Both reusable refs are publishing-vNEXT, a placeholder for the first
publishing tag cut after the .github change; it must be replaced before merge.

docs/building-wheels.md said 21 wheels and publishing-v8; it is 18, and the
pin is named where it lives.
@bdbarnett
bdbarnett merged commit dd84add into main Sep 27, 2026
43 checks passed
@bdbarnett
bdbarnett deleted the caller-side-pypi-publish branch September 27, 2026 00:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant