Skip to content

ci: publish from trusted top-level workflow - #125

Merged
pacharanero merged 1 commit into
livefrom
ci/publish-from-top-level
Sep 6, 2026
Merged

ci: publish from trusted top-level workflow#125
pacharanero merged 1 commit into
livefrom
ci/publish-from-top-level

Conversation

@pacharanero

Copy link
Copy Markdown
Member

Summary

  • keep testing and the single verified artifact build in the reusable package workflow
  • publish from the top-level release workflow so PyPI OIDC and attestations use the supported Trusted Publisher identity
  • add an explicit validated recovery dispatch for failed PyPI publications and document the corrected release model

Evidence

  • v4.6.4 reusable-workflow upload failed first with an attestation identity mismatch and then with invalid-publisher after trusting only the caller
  • PyPI documents reusable workflows as unsupported Trusted Publisher identities
  • s/test tests/distribution/test_validate_release.py -q (11 passed)
  • zizmor --strict-collection . (no medium/high findings; known low $/... suggestions conflict with GitHub's accepted local reusable-workflow syntax)
  • git diff --check

@pacharanero
pacharanero merged commit 71110ef into live Sep 6, 2026
4 checks passed
@pacharanero
pacharanero deleted the ci/publish-from-top-level branch September 6, 2026 04:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant