Commit f570a91
authored
ci(release): use shared Python publishing actions (#706)
Replace the custom production PyPI workflow with the commit-pinned
[`sdk-actions`](https://github.com/braintrustdata/sdk-actions) turnkey
flow.
```text
Before: merge release PR -> automatic publish
After: commit version -> dispatch full SHA -> approve environment -> publish
```
Stable releases now use the merge commit from the version-bump PR, and
the workflow rejects stable
release SHAs outside `main`. Prereleases require the prerelease version
to be committed on the target
branch; off-`main` prerelease branches produce a warning instead of
failing. Both use the `publish` environment, while dry runs use
`publish-dry-run`.
Keep the Python-specific `make install-dev verify-build` checks,
release-channel templating, and
existing `py-sdk-v{version}` tag format. Production publishes also
generate and attest a CycloneDX
SBOM through OIDC trusted publishing.
TestPyPI prereleases, canary publishing, and the canary scheduler are
intentionally unchanged.
Required repository configuration:
- GitHub environments `publish` and `publish-dry-run`
- PyPI trusted publisher scoped to workflow `publish-py-sdk.yaml` and
environment `publish`
- `SLACK_SDK_RELEASE_CHANNEL` visible to this repository
Validated with `actionlint`, the sdk-actions workflow validator and
baseline comparison,
`scripts/ensure-pinned-actions.sh`, and pre-commit.1 parent 6f8182f commit f570a91
6 files changed
Lines changed: 198 additions & 422 deletions
File tree
- .github
- scripts
- workflows
- docs
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
| 64 | + | |
65 | 65 | | |
66 | 66 | | |
0 commit comments