Skip to content

Commit 87031de

Browse files
Add PyPI Trusted Publishing workflow (OIDC, no stored token)
1 parent 4854e8c commit 87031de

1 file changed

Lines changed: 27 additions & 0 deletions

File tree

‎.github/workflows/publish.yml‎

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
name: Publish to PyPI
2+
3+
# Publishes coldpath to PyPI via Trusted Publishing (OIDC) -- no API token, no stored secret.
4+
# Runs when a GitHub release is published, or on demand. Requires a one-time "trusted publisher"
5+
# entry on PyPI (owner: JonathanSolvesProblems, repo: coldpath, workflow: publish.yml).
6+
7+
on:
8+
release:
9+
types: [published]
10+
workflow_dispatch:
11+
12+
permissions:
13+
contents: read
14+
15+
jobs:
16+
publish:
17+
runs-on: ubuntu-latest
18+
permissions:
19+
id-token: write # required for Trusted Publishing
20+
steps:
21+
- uses: actions/checkout@v4
22+
- uses: actions/setup-python@v5
23+
with:
24+
python-version: '3.12'
25+
- run: pip install build
26+
- run: python -m build
27+
- uses: pypa/gh-action-pypi-publish@release/v1

0 commit comments

Comments
 (0)