mirror of
https://github.com/turnstonelabs/turnstone.git
synced 2026-08-26 13:54:48 -06:00
a9898fdd6c
The publish and docker workflows trigger on workflow_run of CI, which fires for every CI completion — including CI runs for pull requests from forks — and always executes with this repo's secrets, tokens, and the pypi environment. The only gate was CI success, so fork-PR CI runs spawned publish jobs in the upstream context; actions/checkout v7's fork-checkout refusal was the only thing that stopped one on 2026-06-30. A fork PR whose head is an upstream-tagged commit would have passed the tag check and reached the upload with valid OIDC. Both workflows now require the triggering CI run to be a push event, from this repository, with head_branch starting with 'v' — CI's push trigger only matches main/stable/* branches and v* tags, so that is necessarily a tag run (verified: tag-push runs report the tag name as head_branch). Checkouts no longer persist the token while the tree's build backend executes, and publishes are no longer cancellable mid-upload (a half-uploaded release cannot be re-run cleanly because PyPI rejects duplicate files). vendor-js hardening in the same pass: gate on the immutable PR author instead of github.actor, require a same-repo head before pushing to the PR branch with contents:write, and pass github.head_ref through env instead of interpolating it into the script body.
72 lines
2.7 KiB
YAML
72 lines
2.7 KiB
YAML
name: Publish to PyPI
|
|
|
|
on:
|
|
workflow_run:
|
|
workflows: ["CI"]
|
|
types: [completed]
|
|
|
|
concurrency:
|
|
group: publish-${{ github.event.workflow_run.head_sha }}
|
|
# Never cancel a publish mid-upload: a half-uploaded release (sdist up,
|
|
# wheel missing) cannot be re-run cleanly because PyPI rejects duplicates.
|
|
cancel-in-progress: false
|
|
|
|
permissions:
|
|
contents: write
|
|
id-token: write
|
|
|
|
jobs:
|
|
publish:
|
|
# workflow_run fires for EVERY CI completion — including CI runs for
|
|
# pull_requests from forks — and always executes here with this repo's
|
|
# secrets, tokens, and the pypi environment. Gate to same-repo tag
|
|
# pushes only: CI's push trigger matches branches main/stable/* and
|
|
# tags v*, so a head_branch starting with "v" is necessarily a tag run.
|
|
if: >-
|
|
github.event.workflow_run.conclusion == 'success' &&
|
|
github.event.workflow_run.event == 'push' &&
|
|
github.event.workflow_run.head_repository.full_name == github.repository &&
|
|
startsWith(github.event.workflow_run.head_branch, 'v')
|
|
runs-on: ubuntu-latest
|
|
environment: pypi
|
|
steps:
|
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
with:
|
|
ref: ${{ github.event.workflow_run.head_sha }}
|
|
fetch-depth: 0
|
|
# python -m build executes the tree's build backend; don't leave
|
|
# the contents:write token sitting in .git/config while it runs.
|
|
persist-credentials: false
|
|
|
|
- name: Resolve release tag
|
|
id: tag
|
|
run: |
|
|
TAG=$(git tag --points-at HEAD | grep '^v' | head -1)
|
|
if [ -z "$TAG" ]; then
|
|
echo "No v* tag at HEAD — skipping publish"
|
|
echo "skip=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "tag=${TAG}" >> "$GITHUB_OUTPUT"
|
|
echo "skip=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
|
|
if: steps.tag.outputs.skip == 'false'
|
|
with:
|
|
python-version: "3.14"
|
|
- run: pip install build
|
|
if: steps.tag.outputs.skip == 'false'
|
|
- run: python -m build
|
|
if: steps.tag.outputs.skip == 'false'
|
|
- uses: pypa/gh-action-pypi-publish@cef221092ed1bacb1cc03d23a2d87d1d172e277b # release/v1
|
|
if: steps.tag.outputs.skip == 'false'
|
|
|
|
- name: Create GitHub Release
|
|
if: steps.tag.outputs.skip == 'false'
|
|
uses: softprops/action-gh-release@718ea10b132b3b2eba29c1007bb80653f286566b # v3
|
|
with:
|
|
tag_name: ${{ steps.tag.outputs.tag }}
|
|
generate_release_notes: true
|
|
draft: false
|
|
prerelease: ${{ contains(steps.tag.outputs.tag, 'a') || contains(steps.tag.outputs.tag, 'b') || contains(steps.tag.outputs.tag, 'rc') }}
|