test rc upload to testpypi #3
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build & Publish | |
| on: | |
| push: | |
| tags: | |
| - "v*" | |
| # workflow 级最小权限;发布 job 再单独提升 id-token | |
| permissions: | |
| id-token: write | |
| contents: read | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| is_prerelease: ${{ steps.tag.outputs.is_prerelease }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| - name: Upgrade packaging tools | |
| run: | | |
| python -m pip install -U pip setuptools wheel | |
| - id: tag | |
| name: Classify tag | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| TAG="${GITHUB_REF_NAME}" | |
| # 仅基于 tag 名判断(不含 refs/tags 前缀) | |
| # 允许: | |
| # vX.Y.Z | |
| # vX.Y.ZaN / vX.Y.ZbN / vX.Y.ZrcN | |
| # vX.Y.Z.devN 或 vX.Y.ZdevN(两种都兼容) | |
| if [[ "$TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+((a|b|rc)[0-9]+|(\.dev|dev)[0-9]+)$ ]]; then | |
| echo "is_prerelease=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "is_prerelease=false" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Build dists | |
| run: | | |
| python -m pip install -U build | |
| python -m build | |
| - name: Upload dist artifact | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: dist | |
| path: dist/* | |
| publish_testpypi: | |
| needs: build | |
| if: needs.build.outputs.is_prerelease == 'true' | |
| runs-on: ubuntu-latest | |
| environment: | |
| name: testpypi | |
| permissions: | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/download-artifact@v4 | |
| with: | |
| name: dist | |
| path: dist | |
| - name: Publish to TestPyPI (Trusted Publishing) | |
| uses: pypa/gh-action-pypi-publish@release/v1 | |
| with: | |
| repository-url: https://test.pypi.org/legacy/ | |
| skip-existing: true | |
| verbose: true | |
| publish_pypi: | |
| needs: build | |
| if: needs.build.outputs.is_prerelease != 'true' | |
| runs-on: ubuntu-latest | |
| environment: | |
| name: pypi | |
| url: https://pypi.org/p/python-tty | |
| permissions: | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/download-artifact@v4 | |
| with: | |
| name: dist | |
| path: dist | |
| - name: Publish to PyPI (Trusted Publishing) | |
| uses: pypa/gh-action-pypi-publish@release/v1 |