Skip to content

ci: publish to PyPI from release tags #29

ci: publish to PyPI from release tags

ci: publish to PyPI from release tags #29

Workflow file for this run

name: CI
on:
push:
pull_request:
jobs:
test-and-build:
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Set up uv
uses: astral-sh/setup-uv@v4
- name: Install dependencies
run: uv sync --group dev
- name: Reject macOS junk files
run: |
if git ls-files | grep -E '(^__MACOSX/|(^|/)\.DS_Store$|(^|/)\._)'; then
echo "Remove macOS archive/junk files before merging."
exit 1
fi
- name: Run non-integration tests
run: uv run pytest tests -m "not integration"
- name: Smoke-test CLI help
run: uv run dataref --help
- name: Build package
run: uv build
- name: Clean-tree check
run: |
if [ -n "$(git status --porcelain)" ]; then
echo "Working tree is dirty after build:"
git status
git diff
exit 1
fi
- name: Upload wheel artifact
uses: actions/upload-artifact@v4
with:
name: wheel
path: dist/*.whl
if-no-files-found: error
s3-integration:
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Set up uv
uses: astral-sh/setup-uv@v4
- name: Install dependencies
run: uv sync --group dev
- name: Run S3 integration tests against MiniStack
run: bash scripts/run_s3_integration.sh
isolated-install-smoke:
needs: [test-and-build]
runs-on: ubuntu-latest
steps:
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Download wheel artifact
uses: actions/download-artifact@v4
with:
name: wheel
path: dist
- name: Isolated install and smoke
run: |
set -euo pipefail
WHEEL=$(ls dist/*.whl | head -1)
python -m venv /tmp/smoke-venv
/tmp/smoke-venv/bin/pip install "$WHEEL"
echo "=== dataref --help ==="
/tmp/smoke-venv/bin/dataref --help
echo "=== dataref --version ==="
/tmp/smoke-venv/bin/dataref --version 2>/dev/null || true
echo "=== basic commit smoke ==="
TMPDIR=$(mktemp -d)
echo "smoke-test-content" > "$TMPDIR/smoke.txt"
/tmp/smoke-venv/bin/dataref commit --repo "$TMPDIR" -m "smoke" > /dev/null
echo "Isolated install smoke test passed."
release-gate:
if: startsWith(github.ref, 'refs/tags/v')
needs: [test-and-build, s3-integration, isolated-install-smoke]
runs-on: ubuntu-latest
permissions:
id-token: write # OIDC -> PyPI trusted publishing (no API token)
contents: read
steps:
- name: Check out repository
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Set up uv
uses: astral-sh/setup-uv@v4
- name: Verify tag matches package version
run: |
set -euo pipefail
TAG_VERSION="${GITHUB_REF_NAME#v}"
PACKAGE_VERSION="$(sed -n 's/^version = "\(.*\)"/\1/p' pyproject.toml)"
if [ "$TAG_VERSION" != "$PACKAGE_VERSION" ]; then
echo "Tag ${GITHUB_REF_NAME} does not match pyproject version ${PACKAGE_VERSION}" >&2
exit 1
fi
echo "Releasing dataref ${PACKAGE_VERSION}"
- name: Build package
run: uv build
- name: Publish to PyPI
run: uv publish --publish-url https://upload.pypi.org/legacy/ --check-url https://pypi.org/pypi/dataref/json