From 57ff357312cc5e0abeb2ca6e214b7252cba43cee Mon Sep 17 00:00:00 2001 From: Ratul Maharaj <56479869+RatulMaharaj@users.noreply.github.com> Date: Thu, 25 Jun 2026 17:09:27 +0200 Subject: [PATCH 1/2] ci: attach built wheel + sdist to the GitHub release MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit On a published release, upload the `uv build` artifacts (wheel + sdist) as release assets so consumers can pin a direct `.whl` URL: datamaker-py @ https://github.com/automators-com/datamaker-py/releases/download//datamaker_py--py3-none-any.whl Because the URL ends in `.whl`, uv/pip install it as a wheel with no build step — the DataMaker desktop runner needs this to provision its venv fully offline (URL-locked sdists currently force a build at install time). The repo is public, so the asset URL needs no auth. Also gate the existing PyPI publish job behind `vars.PUBLISH_TO_PYPI == 'true'`: PyPI trusted publishing isn't set up yet (the project isn't on PyPI), so the job would fail on every release. It's now opt-in until configured. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01TMwtcrQZ2WSMZB7wZYM6za --- .github/workflows/python-publish.yml | 25 +++++++++++++++++++++++-- 1 file changed, 23 insertions(+), 2 deletions(-) diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml index 4697318..481619a 100644 --- a/.github/workflows/python-publish.yml +++ b/.github/workflows/python-publish.yml @@ -19,6 +19,10 @@ jobs: release-build: runs-on: ubuntu-latest + # Needed so we can attach the built wheel + sdist to the GitHub release. + permissions: + contents: write + steps: - uses: actions/checkout@v4 @@ -29,11 +33,11 @@ jobs: uses: actions/setup-python@v5 with: python-version: "3.14" - + - name: Install dependencies run: | uv sync --all-extras --dev - + - name: Build release distributions run: | uv build @@ -44,8 +48,25 @@ jobs: name: release-dists path: dist/ + # Attach the wheel (and sdist) to the GitHub release so consumers can pin a + # direct `.whl` URL, e.g. + # datamaker-py @ https://github.com/automators-com/datamaker-py/releases/download//datamaker_py--py3-none-any.whl + # Because the URL ends in `.whl`, uv/pip install it as a wheel with NO build + # step (the DataMaker desktop runner needs this to provision its venv fully + # offline). The repo is public, so the asset URL needs no auth. + - name: Attach distributions to the GitHub release + env: + GH_TOKEN: ${{ github.token }} + run: | + gh release upload "${{ github.event.release.tag_name }}" dist/*.whl dist/*.tar.gz --clobber + pypi-publish: runs-on: ubuntu-latest + # Opt-in: PyPI trusted publishing must be configured (project registered on + # PyPI with this repo's `pypi` environment as a trusted publisher) before + # this can succeed. Until then it's disabled so releases don't fail on it. + # Enable by setting the repo variable PUBLISH_TO_PYPI=true. + if: ${{ vars.PUBLISH_TO_PYPI == 'true' }} needs: - release-build permissions: From 2107f31df7713e31ca4368f0a3f616237a3cdeb2 Mon Sep 17 00:00:00 2001 From: Ratul Maharaj <56479869+RatulMaharaj@users.noreply.github.com> Date: Thu, 25 Jun 2026 17:10:17 +0200 Subject: [PATCH 2/2] ci: build + attach wheel/sdist to GitHub release (drop PyPI publishing) On a published release, build with `uv build` and upload the wheel + sdist as GitHub release assets, so consumers can pin a direct `.whl` URL and install with no build step (the desktop runner provisions its venv fully offline this way). Removes the PyPI trusted-publishing job entirely: the project isn't on PyPI and we're standardizing on GitHub release assets. Co-Authored-By: Claude Opus 4.8 Claude-Session: https://claude.ai/code/session_01TMwtcrQZ2WSMZB7wZYM6za --- .github/workflows/python-publish.yml | 55 +--------------------------- 1 file changed, 2 insertions(+), 53 deletions(-) diff --git a/.github/workflows/python-publish.yml b/.github/workflows/python-publish.yml index 481619a..c1d37e3 100644 --- a/.github/workflows/python-publish.yml +++ b/.github/workflows/python-publish.yml @@ -1,10 +1,5 @@ -# This workflow will upload a Python Package to PyPI when a release is created -# For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-python#publishing-to-package-registries - -# This workflow uses actions that are not certified by GitHub. -# They are provided by a third-party and are governed by -# separate terms of service, privacy policy, and support -# documentation. +# On a published GitHub release, build the package and attach the wheel + sdist +# as release assets so consumers can pin a direct `.whl` URL (no PyPI involved). name: Upload Python Package @@ -34,20 +29,10 @@ jobs: with: python-version: "3.14" - - name: Install dependencies - run: | - uv sync --all-extras --dev - - name: Build release distributions run: | uv build - - name: Upload distributions - uses: actions/upload-artifact@v4 - with: - name: release-dists - path: dist/ - # Attach the wheel (and sdist) to the GitHub release so consumers can pin a # direct `.whl` URL, e.g. # datamaker-py @ https://github.com/automators-com/datamaker-py/releases/download//datamaker_py--py3-none-any.whl @@ -59,39 +44,3 @@ jobs: GH_TOKEN: ${{ github.token }} run: | gh release upload "${{ github.event.release.tag_name }}" dist/*.whl dist/*.tar.gz --clobber - - pypi-publish: - runs-on: ubuntu-latest - # Opt-in: PyPI trusted publishing must be configured (project registered on - # PyPI with this repo's `pypi` environment as a trusted publisher) before - # this can succeed. Until then it's disabled so releases don't fail on it. - # Enable by setting the repo variable PUBLISH_TO_PYPI=true. - if: ${{ vars.PUBLISH_TO_PYPI == 'true' }} - needs: - - release-build - permissions: - # IMPORTANT: this permission is mandatory for trusted publishing - id-token: write - - # Dedicated environments with protections for publishing are strongly recommended. - # For more information, see: https://docs.github.com/en/actions/deployment/targeting-different-environments/using-environments-for-deployment#deployment-protection-rules - environment: - name: pypi - # OPTIONAL: uncomment and update to include your PyPI project URL in the deployment status: - url: https://pypi.org/p/datamaker-py - # - # ALTERNATIVE: if your GitHub Release name is the PyPI project version string - # ALTERNATIVE: exactly, uncomment the following line instead: - # url: https://pypi.org/project/YOURPROJECT/${{ github.event.release.name }} - - steps: - - name: Retrieve release distributions - uses: actions/download-artifact@v4 - with: - name: release-dists - path: dist/ - - - name: Publish release distributions to PyPI - uses: pypa/gh-action-pypi-publish@release/v1 - with: - packages-dir: dist/