ci: publish to PyPI via trusted publishing; build version images on release (#417)

* ci: publish to PyPI via trusted publishing; build version images on release

* ci: pin publish actions to commit SHAs; extend version guard to docker and manual dispatch

* ci: disable setup-uv cache in the publish workflow
This commit is contained in:
Xi Zhang
2026-08-09 17:31:17 +01:00
committed by GitHub
parent 12adc62868
commit e086f76da7
2 changed files with 84 additions and 1 deletions
+17 -1
View File
@@ -3,7 +3,10 @@ name: Docker
on:
push:
branches: ["main"]
tags: ["v*"]
# Version images build when a GitHub Release is published — the same event
# that triggers the PyPI upload (publish.yml), so the two channels stay in sync.
release:
types: [published]
pull_request:
paths:
- "Dockerfile"
@@ -32,6 +35,19 @@ jobs:
steps:
- uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1
# Same guard as publish.yml — a release whose tag mismatches pyproject
# must not publish versioned images either.
- name: Guard — package version must match the release tag
if: github.event_name == 'release'
run: |
VERSION=$(grep -m1 '^version = ' pyproject.toml | sed -E 's/^version = "(.*)"/\1/')
TAG="${GITHUB_REF_NAME#v}"
echo "pyproject version: $VERSION | release tag: $TAG"
if [ "$VERSION" != "$TAG" ]; then
echo "::error::pyproject version ($VERSION) does not match release tag ($TAG); refusing to publish images."
exit 1
fi
- uses: docker/setup-qemu-action@c7c53464625b32c7a7e944ae62b3e17d2b600130 # v3.7.0
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0