Skip to content

Harden workflow

Harden workflow #1

Workflow file for this run

name: Publish to PyPI
on:
push:
tags:
- "v*"
# Rerun workflow manually if the publish fails without new tag
workflow_dispatch:
permissions:
contents: read
jobs:
build:
name: Build distributions
runs-on: ubuntu-latest
steps:
- name: Check out repository
uses: actions/checkout@v7
with:
persist-credentials: false
- name: Set up Python
uses: actions/setup-python@v7
with:
python-version: "3.x"
- name: Install build
run: python3 -m pip install --upgrade build
- name: Build distributions
run: python3 -m build
- name: Upload distributions
uses: actions/upload-artifact@v7
with:
name: distributions
path: dist/
if-no-files-found: error
publish:
name: Publish to PyPI
needs: build
runs-on: ubuntu-latest
environment:
name: release
url: "https://pypi.org/project/python-lsp-ruff"
permissions:
id-token: write
steps:
- name: Download distributions
uses: actions/download-artifact@v8
with:
name: distributions
path: dist/
- name: Publish distributions to PyPI
uses: pypa/gh-action-pypi-publish@release/v1