diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml index 4697318..c1d37e3 100644 --- a/.github/workflows/python-publish.yml +++ b/.github/workflows/python-publish.yml @@ -1,10 +1,5 @@ -# This workflow will upload a Python Package to PyPI when a release is created -# For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-python#publishing-to-package-registries - -# This workflow uses actions that are not certified by GitHub. -# They are provided by a third-party and are governed by -# separate terms of service, privacy policy, and support -# documentation. +# On a published GitHub release, build the package and attach the wheel + sdist +# as release assets so consumers can pin a direct `.whl` URL (no PyPI involved). name: Upload Python Package @@ -19,6 +14,10 @@ jobs: release-build: runs-on: ubuntu-latest + # Needed so we can attach the built wheel + sdist to the GitHub release. + permissions: + contents: write + steps: - uses: actions/checkout@v4 @@ -29,48 +28,19 @@ jobs: uses: actions/setup-python@v5 with: python-version: "3.14" - - - name: Install dependencies - run: | - uv sync --all-extras --dev - + - name: Build release distributions run: | uv build - - name: Upload distributions - uses: actions/upload-artifact@v4 - with: - name: release-dists - path: dist/ - - pypi-publish: - runs-on: ubuntu-latest - needs: - - release-build - permissions: - # IMPORTANT: this permission is mandatory for trusted publishing - id-token: write - - # Dedicated environments with protections for publishing are strongly recommended. - # For more information, see: https://docs.github.com/en/actions/deployment/targeting-different-environments/using-environments-for-deployment#deployment-protection-rules - environment: - name: pypi - # OPTIONAL: uncomment and update to include your PyPI project URL in the deployment status: - url: https://pypi.org/p/datamaker-py - # - # ALTERNATIVE: if your GitHub Release name is the PyPI project version string - # ALTERNATIVE: exactly, uncomment the following line instead: - # url: https://pypi.org/project/YOURPROJECT/${{ github.event.release.name }} - - steps: - - name: Retrieve release distributions - uses: actions/download-artifact@v4 - with: - name: release-dists - path: dist/ - - - name: Publish release distributions to PyPI - uses: pypa/gh-action-pypi-publish@release/v1 - with: - packages-dir: dist/ + # Attach the wheel (and sdist) to the GitHub release so consumers can pin a + # direct `.whl` URL, e.g. + # datamaker-py @ https://github.com/automators-com/datamaker-py/releases/download//datamaker_py--py3-none-any.whl + # Because the URL ends in `.whl`, uv/pip install it as a wheel with NO build + # step (the DataMaker desktop runner needs this to provision its venv fully + # offline). The repo is public, so the asset URL needs no auth. + - name: Attach distributions to the GitHub release + env: + GH_TOKEN: ${{ github.token }} + run: | + gh release upload "${{ github.event.release.tag_name }}" dist/*.whl dist/*.tar.gz --clobber