Skip to content

Align PyPI publish workflow OIDC claims with trusted publisher configuration - #81

Merged
pedrohcgs merged 2 commits into
mainfrom
copilot/fix-failing-github-actions-job
Jul 2, 2026
Merged

pedrohcgs merged 2 commits into
mainfrom
copilot/fix-failing-github-actions-job

Conversation

Copilot AI commented Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

The build-and-publish GitHub Actions job was failing during PyPI trusted publishing with invalid-publisher. The job token claims showed environment: MISSING, which prevented claim matching on the PyPI publisher side.

  • Root cause

    • build-and-publish in .github/workflows/pypi.yml did not run under the expected GitHub environment, so OIDC claims did not include the environment required by trusted publishing.
  • Change

    • Added the PyPI environment to the publish job:
      • environment: pypi
  • Workflow impact

    • Ensures the OIDC token includes environment-scoped claims expected by the configured PyPI trusted publisher.
    • Keeps existing publish behavior intact (skip-existing: true, same build/check/publish steps).
jobs:
  build-and-publish:
    runs-on: ubuntu-latest
    environment: pypi
    permissions:
      id-token: write

Copilot AI changed the title [WIP] Fix failing GitHub Actions job build-and-publish Align PyPI publish workflow OIDC claims with trusted publisher configuration Jul 2, 2026
Copilot AI requested a review from pedrohcgs July 2, 2026 18:58
@pedrohcgs
pedrohcgs marked this pull request as ready for review July 2, 2026 19:01
Copilot AI review requested due to automatic review settings July 2, 2026 19:01

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR fixes PyPI Trusted Publishing failures for the csdid package by ensuring the GitHub Actions OIDC token includes the expected environment claim. It does so by running the publish job under the pypi GitHub environment, aligning workflow token claims with the configured PyPI trusted publisher.

Changes:

  • Add environment: pypi to the build-and-publish job in the PyPI publish workflow to ensure correct OIDC claim matching.

@pedrohcgs
pedrohcgs merged commit 7ad8bca into main Jul 2, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants