Skip to content

Publish caw to PyPI via trusted publishing #34

Description

@qinhaihong-red

What to build

Extend the release pipeline so that every GitHub Release also publishes the built
sdist and wheel to PyPI using Trusted Publishing (OIDC) — no long-lived API tokens
stored in the repo.

Human prerequisites that no agent can do (hence HITL):

  • Check availability of the caw name on PyPI and claim it (or decide on an
    alternative distribution name — that decision affects project metadata)
  • Create the PyPI project and configure the trusted publisher binding
    (repository + workflow + environment)
  • Optionally register a TestPyPI counterpart for a dry-run path first

Once the human setup exists, the workflow change itself is small: a publish job
gated on the release event, using the official PyPI publish action with OIDC.

Acceptance criteria

  • PyPI project exists and a trusted publisher is configured for this repository's release workflow (human)
  • The release pipeline publishes sdist + wheel to PyPI when a GitHub Release is produced (by either trigger path), and a publish failure fails the workflow visibly
  • After the first published release, uvx caw --help works from a clean machine
  • The distribution name decision is recorded if it differs from caw

Blocked by

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions