packaging icon indicating copy to clipboard operation
packaging copied to clipboard

Automate releasing

Open brettcannon opened this issue 4 years ago • 6 comments

As https://packaging.pypa.io/en/latest/development/release-process/ points out, it's already mostly automated. I think if we added a PyPI token and then used https://github.blog/changelog/2020-07-06-github-actions-manual-triggers-with-workflow_dispatch/ with the version number to release as the sole input we can make it so we can cut a release entirely in the browser.

brettcannon avatar Oct 13 '20 19:10 brettcannon

Are you picturing this as a release.yml in .github/workflows? With the GPG password and API token mentioned by https://packaging.pypa.io/en/latest/development/release-process.html as secrets stored on GitHub? (A bit like https://github.com/pypa/gh-action-pypi-publish, but with workflow_dispatch like you mentioned?)

dHannasch avatar Jun 21 '21 16:06 dHannasch

Yeah, basically. Since there are multiple maintainers of this project, all of whom have the ability/clearance to do a release, automating it so it's as much of a button click as possible would be good.

brettcannon avatar Jun 21 '21 23:06 brettcannon

x-ref https://github.com/pypa/packaging/issues/273

pradyunsg avatar Apr 20 '22 19:04 pradyunsg

Noting for whenever we get to this: the current best practice is to use trusted publishers, which can also be combined with workflows blocking on approvals.

pradyunsg avatar Oct 17 '23 09:10 pradyunsg

Yep, I was actually thinking about this issue last week when I was setting trusted publishers up on some of my personal projects. 🙂

brettcannon avatar Oct 18 '23 01:10 brettcannon

With the GPG password

GPG support has been deprecated on the PyPI but we've added a Sigstore usage example to my PyPUG guide: https://packaging.python.org/en/latest/guides/publishing-package-distribution-releases-using-github-actions-ci-cd-workflows/#signing-the-distribution-packages. It's passwordless and is integrated the same way as trusted publishing — through OIDC.

webknjaz avatar Mar 19 '24 15:03 webknjaz