Files
SmartThings-Local/.github/workflows/publish.yml
T
Quite Yellow e0622eb087 ci(publish): bump actions off deprecated Node 20 runtimes (#18)
GitHub is deprecating the Node 20 action runtime; checkout@v4,
setup-python@v5, and upload/download-artifact@v4 all run on it and
were being auto-forced to Node 24 with a warning. Bump each to its
current major (checkout@v7, setup-python@v7, upload-artifact@v7,
download-artifact@v8), all of which run natively on Node 24.
2026-08-01 11:28:14 +01:00

51 lines
1.4 KiB
YAML

name: Publish to PyPI
# Publishes smartthings-local to PyPI on a version tag (v1.2.3).
# Uses PyPI Trusted Publishing (OIDC) — no API token is stored in the repo.
# One-time setup on PyPI: add a trusted publisher for this repo pointing at
# workflow `publish.yml` and environment `pypi`.
on:
push:
tags:
- "v*"
jobs:
build:
name: Build sdist + wheel
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0 # hatch-vcs needs full history + tags to derive the version
- uses: actions/setup-python@v7
with:
python-version: "3.12"
- run: python -m pip install --upgrade build
- run: python -m build
- name: Verify the built version matches the tag
run: |
ls -l dist/
version="${GITHUB_REF_NAME#v}"
if ! ls dist/ | grep -q "smartthings_local-${version}"; then
echo "Built artifacts do not match tag version ${version}"; exit 1
fi
- uses: actions/upload-artifact@v7
with:
name: dist
path: dist/
publish:
name: Publish to PyPI
needs: build
runs-on: ubuntu-latest
environment: pypi
permissions:
id-token: write # required for Trusted Publishing (OIDC)
steps:
- uses: actions/download-artifact@v8
with:
name: dist
path: dist/
- uses: pypa/gh-action-pypi-publish@release/v1