Skip to content

Commit 29e409e

Browse files
authored
fix(ci): make the PyPI publish workflow actually runnable (#537)
Three things independently prevented a release: - Both jobs were gated on `github.repository_owner == 'twilio'`, carried over from the reference implementation. This repo is under segmentio, so a published release skipped both jobs and reported success having uploaded nothing. The guard still blocks forks, just against the right owner. - The runner expression fell through to bare ubuntu-latest, which gets no runner in this org. - Tag validation required a v prefix; every tag here is bare (2.3.6, 2.3.5). Both forms are accepted now. RELEASING.md described a local twine upload and a bare tag push. Neither reaches the OIDC path, and `release: published` does not fire on a tag push at all, so it now says to cut a GitHub Release and to bump pyproject.toml — which is the file the tag is validated against.
1 parent 465c2c9 commit 29e409e

2 files changed

Lines changed: 28 additions & 11 deletions

File tree

‎.github/workflows/publish.yml‎

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,10 @@ env:
1010
jobs:
1111
test:
1212
name: Test - Python ${{ matrix.python-version }}
13-
runs-on: ${{ github.repository_owner == 'twilio' && 'ubuntu-x64' || 'ubuntu-latest' }}
14-
if: github.repository_owner == 'twilio'
13+
runs-on: ubuntu-x64
14+
# Guards against forks publishing. Bare ubuntu-latest gets no runner in
15+
# this org, so the fork branch of the old expression was unusable anyway.
16+
if: github.repository_owner == 'segmentio'
1517
permissions:
1618
contents: read
1719
id-token: write
@@ -34,8 +36,10 @@ jobs:
3436
deploy:
3537
name: Publish to PyPI
3638
needs: [test]
37-
runs-on: ${{ github.repository_owner == 'twilio' && 'ubuntu-x64' || 'ubuntu-latest' }}
38-
if: github.repository_owner == 'twilio'
39+
runs-on: ubuntu-x64
40+
# Guards against forks publishing. Bare ubuntu-latest gets no runner in
41+
# this org, so the fork branch of the old expression was unusable anyway.
42+
if: github.repository_owner == 'segmentio'
3943
environment: production
4044
permissions:
4145
contents: read
@@ -53,8 +57,10 @@ jobs:
5357
- name: Validate tag format and version match
5458
run: |
5559
TAG="${GITHUB_REF#refs/tags/}"
56-
if [[ ! "$TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+ ]]; then
57-
echo "::error::Release tag must be in the form v1.2.3 (got '$TAG')"
60+
# This repo's tags carry no v prefix (2.3.6, 2.3.5, ...); accept both
61+
# so the existing convention keeps working.
62+
if [[ ! "$TAG" =~ ^v?[0-9]+\.[0-9]+\.[0-9]+ ]]; then
63+
echo "::error::Release tag must be X.Y.Z or vX.Y.Z (got '$TAG')"
5864
exit 1
5965
fi
6066
VERSION="${TAG#v}"

‎RELEASING.md‎

Lines changed: 16 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,20 @@
11
Releasing
22
=========
33

4-
1. Update `VERSION` in `segment/analytics/version.py` to the new version.
5-
2. Update the `HISTORY.md` for the impending release.
4+
Publishing happens in CI through PyPI Trusted Publishing (OIDC). There is no
5+
PyPI token to hold locally, and `make release` is not the release path — it
6+
uploads with a stored credential and skips provenance.
7+
8+
1. Update the version in **both** `pyproject.toml` and
9+
`segment/analytics/version.py`. The publish workflow validates the release
10+
tag against `pyproject.toml` and fails if the two disagree.
11+
2. Update `HISTORY.md`.
612
3. `git commit -am "Release X.Y.Z."` (where X.Y.Z is the new version)
7-
4. `git tag -a X.Y.Z -m "Version X.Y.Z"` (where X.Y.Z is the new version).
8-
5. `git push && git push --tags`
9-
6. `make release`.
13+
4. Open a PR and merge it to `master`.
14+
5. Tag the merged commit and push it:
15+
`git tag -a X.Y.Z -m "Version X.Y.Z" && git push --tags`
16+
6. Create a **GitHub Release** for that tag. The workflow triggers on
17+
`release: published`; pushing the tag by itself does not start it.
18+
19+
The workflow then runs the test matrix, builds with `uv`, and uploads to PyPI
20+
with `--trusted-publishing=always`.

0 commit comments

Comments
 (0)