GeoDebug releases are tag-driven and publish to both GitHub Releases and PyPI.
GeoDebug uses PyPI Trusted Publishing through GitHub Actions. No long-lived PyPI API token is stored in GitHub.
In the PyPI publisher configuration for the geodebug project, configure:
- Owner:
GeoGeekLab - Repository:
geodebug - Workflow:
release.yml - Environment:
pypi
For the first publication, use a pending trusted publisher if the PyPI project does not exist yet.
- Ensure CI is green on
main. - Confirm
CHANGELOG.mdcontains the release entry. - Confirm
src/geodebug/version.pycontains the release version. - Create and push a matching
vX.Y.Ztag. - The release workflow verifies the tag/version match.
- The workflow builds the sdist and wheel and runs
twine check. - The workflow creates the GitHub Release with both distribution artifacts.
- A separate job publishes the exact same distributions to PyPI using OIDC trusted publishing.
The publish job is intentionally isolated behind the GitHub pypi environment and receives only the id-token: write permission required for trusted publishing.