Release 2.4.0 #2
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish | |
| on: | |
| release: | |
| types: [published] | |
| env: | |
| ARTIFACTORY_URL: ${{ vars.ARTIFACTORY_URL }} | |
| jobs: | |
| test: | |
| name: Test - Python ${{ matrix.python-version }} | |
| runs-on: ubuntu-x64 | |
| # Guards against forks publishing. Bare ubuntu-latest gets no runner in | |
| # this org, so the fork branch of the old expression was unusable anyway. | |
| if: github.repository_owner == 'segmentio' | |
| permissions: | |
| contents: read | |
| id-token: write | |
| timeout-minutes: 20 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| python-version: ["3.9", "3.10", "3.11", "3.12", "3.13"] | |
| steps: | |
| - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 | |
| - name: Authenticate with Artifactory | |
| uses: ./.github/actions/artifactory-oidc | |
| - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| - run: pip install uv | |
| - run: uv sync --frozen --all-extras | |
| - run: uv run pytest | |
| deploy: | |
| name: Publish to PyPI | |
| needs: [test] | |
| runs-on: ubuntu-x64 | |
| # Guards against forks publishing. Bare ubuntu-latest gets no runner in | |
| # this org, so the fork branch of the old expression was unusable anyway. | |
| if: github.repository_owner == 'segmentio' | |
| environment: production | |
| permissions: | |
| contents: read | |
| id-token: write | |
| attestations: write | |
| steps: | |
| - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 | |
| - name: Authenticate with Artifactory | |
| uses: ./.github/actions/artifactory-oidc | |
| - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 | |
| with: | |
| python-version: "3.12" | |
| - run: pip install uv | |
| - name: Validate tag format and version match | |
| run: | | |
| TAG="${GITHUB_REF#refs/tags/}" | |
| # This repo's tags carry no v prefix (2.3.6, 2.3.5, ...); accept both | |
| # so the existing convention keeps working. | |
| if [[ ! "$TAG" =~ ^v?[0-9]+\.[0-9]+\.[0-9]+ ]]; then | |
| echo "::error::Release tag must be X.Y.Z or vX.Y.Z (got '$TAG')" | |
| exit 1 | |
| fi | |
| VERSION="${TAG#v}" | |
| PKG_VERSION=$(python -c " | |
| import tomllib | |
| with open('pyproject.toml', 'rb') as f: | |
| print(tomllib.load(f)['project']['version']) | |
| ") | |
| if [ "$VERSION" != "$PKG_VERSION" ]; then | |
| echo "::error::Tag $TAG does not match pyproject.toml version $PKG_VERSION" | |
| exit 1 | |
| fi | |
| - name: Build package | |
| run: uv build | |
| - name: Publish to PyPI | |
| run: | | |
| pip install "twine>=5.0" | |
| twine upload --non-interactive --repository pypi dist/* |