What to build
Extend the release pipeline so that every GitHub Release also publishes the built
sdist and wheel to PyPI using Trusted Publishing (OIDC) — no long-lived API tokens
stored in the repo.
Human prerequisites that no agent can do (hence HITL):
- Check availability of the
caw name on PyPI and claim it (or decide on an
alternative distribution name — that decision affects project metadata)
- Create the PyPI project and configure the trusted publisher binding
(repository + workflow + environment)
- Optionally register a TestPyPI counterpart for a dry-run path first
Once the human setup exists, the workflow change itself is small: a publish job
gated on the release event, using the official PyPI publish action with OIDC.
Acceptance criteria
Blocked by
What to build
Extend the release pipeline so that every GitHub Release also publishes the built
sdist and wheel to PyPI using Trusted Publishing (OIDC) — no long-lived API tokens
stored in the repo.
Human prerequisites that no agent can do (hence HITL):
cawname on PyPI and claim it (or decide on analternative distribution name — that decision affects project metadata)
(repository + workflow + environment)
Once the human setup exists, the workflow change itself is small: a publish job
gated on the release event, using the official PyPI publish action with OIDC.
Acceptance criteria
uvx caw --helpworks from a clean machinecawBlocked by