FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

ci(workflows): restrict releases to the upstream repository · pythonnative/pythonnative@01838d9 · GitHub

ci(workflows): restrict releases to the upstream repository #66

ci(workflows): restrict releases to the upstream repository

ci(workflows): restrict releases to the upstream repository #66

Workflow file for this run

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
name: Release
on:
push:
branches: [main]
workflow_dispatch:
jobs:
release:
if: github.repository == 'pythonnative/pythonnative'
name: Semantic Release
runs-on: ubuntu-latest
concurrency:
group: release
cancel-in-progress: false
permissions:
contents: write
id-token: write
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up uv
uses: astral-sh/setup-uv@v10.0.1
with:
enable-cache: true
python-version: '3.13'
# TEMPORARY: inlined replacement for the
# python-semantic-release/python-semantic-release@v9 action. That
# action builds its Docker image at job time with GitPython
# unpinned, and GitPython 3.1.60 (2026-08-25) removed
# Actor.name_email_regex, which crashes every semantic-release
# config load (python-semantic-release issue #1475). This step
# mirrors the action: same git identity, same `version` command,
# and a `released` output for the steps below. Restore the action
# once the fix (python-semantic-release PR #1477) is released.
- name: Python Semantic Release
id: release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
git config user.name "github-actions"
git config user.email "actions@github.com"
uv tool install "python-semantic-release==9.21.2" --with "gitpython<3.1.60"
tags_before=$(git tag | wc -l)
semantic-release -v version
tags_after=$(git tag | wc -l)
if [ "$tags_after" -gt "$tags_before" ]; then
echo "released=true" >> "$GITHUB_OUTPUT"
else
echo "released=false" >> "$GITHUB_OUTPUT"
fi
# The distributions come from `build_command` in
# [tool.semantic_release], which runs `uv build` after PSR stamps the
# new version, so there is no separate build step here.
- name: Publish to PyPI
if: steps.release.outputs.released == 'true'
uses: pypa/gh-action-pypi-publish@release/v1
with:
skip-existing: true

Back | FazBrowse Home | New Git URL