Skip to content

ci: publish to PyPI with Trusted Publishing and separate build/publish jobs - #7342

Open
gypsy5oul wants to merge 1 commit into
google:mainfrom
gypsy5oul:ci/pypi-trusted-publishing
Open

gypsy5oul wants to merge 1 commit into
google:mainfrom
gypsy5oul:ci/pypi-trusted-publishing

Conversation

@gypsy5oul

Copy link
Copy Markdown

Please ensure you have read the contribution guide before creating a pull request.

Link to Issue or Description of Change

1. Link to an existing issue (if applicable):

Problem:
release-publish.yml publishes google-adk with a long-lived PyPI token (secrets.PYPI_TOKEN). The token shares one job with build tooling (uv cache enabled) and RELEASE_PAT. Releases have no PEP 740 attestations; google-adk 2.10.0 has none on PyPI.

Solution:
Split the workflow into three jobs.

  • build (contents: read)
    • Keeps the existing branch validation, version detection, v1 PEP 440 mapping and uv build, unchanged.
    • Turns the uv cache off in the release job, so a poisoned cache can't reach a published build.
    • Uploads dist/ as an artifact.
  • publish (id-token: write only, pypi environment)
    • Downloads dist/ and uploads it with PyPI Trusted Publishing via pypa/gh-action-pypi-publish (pinned to a commit SHA).
    • PEP 740 attestations are generated automatically.
  • merge-back
    • Creates the merge-back PR with RELEASE_PAT, exactly as before.
    • Uses the version outputs from build, plus GH_REPO because there's no checkout in this job.

Also:

  • Workflow-level permissions go from contents: write + pull-requests: write to contents: read. The merge-back step already authenticates with RELEASE_PAT, so it doesn't use GITHUB_TOKEN write access; please confirm this matches your setup.
  • secrets.PYPI_TOKEN is no longer used.

Maintainer action needed before the next release. On PyPI, open google-adk → Manage → Publishing and add a trusted publisher:

Field Value
Owner google
Repository adk-python
Workflow release-publish.yml
Environment pypi

After the first successful release, the PYPI_TOKEN secret can be revoked and deleted.

Testing Plan

This change only touches a release workflow; no library code changes, so there are no unit tests to add.

  • actionlint: passes.
  • zizmor --offline: 0 findings on the new workflow.
  • uv build from a clean checkout with the same commands: builds google_adk-2.10.0.tar.gz and google_adk-2.10.0-py3-none-any.whl, as today.
  • Suggested verification after merge: run the workflow for the next release. publish should upload via OIDC, the PyPI file pages should show attestations, and merge-back should open the sync PR as before.

Checklist

  • I have read the CONTRIBUTING.md document.
  • I have performed a self-review of my own code.
  • I have commented my code, particularly in hard-to-understand areas.
  • I have added tests that prove my fix is effective or that my feature works. (N/A: CI workflow only)
  • New and existing unit tests pass locally with my changes. (N/A: no code changes)
  • I have manually tested my changes end-to-end. (Needs a real release run; see the Testing Plan)
  • Any dependent changes have been merged and published in downstream modules.

Additional context

Related: #6601 proposed id-token: write for Trusted Publishing, but only its other changes were imported (0075954). This PR is independent of #7304 and does not change the check gate removed in e143cce.

This follows PyPA's recommended layout of separate build and publish jobs, with Trusted Publishing: https://docs.pypi.org/trusted-publishers/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Publish google-adk to PyPI with Trusted Publishing (no stored token, add attestations)

2 participants