Releasing¶
Releases are built and published by .github/workflows/release.yml when a version tag is pushed.
One-time setup¶
- On PyPI, add a pending trusted publisher for the project
agentic-chaos-security(the PyPI nameagentic-chaosbelongs to an unrelated project): ownerRicoKomenda, repositoryagentic-chaos, workflowrelease.yml, environmentpypi. No API token is stored anywhere. The first release creates the project. - In the GitHub repository settings, create the environment
pypiand require a reviewer for it. - For the docs site: Settings > Pages > Source "GitHub Actions", then add the repository variable
DOCS_DEPLOY=true. - Optionally do the same for TestPyPI (environment
testpypi) to rehearse a release.
Each release¶
- Update
versioninpyproject.toml(the package reads its version from its metadata). - Move the
Unreleasedentries inCHANGELOG.mdunder a heading for the new version. - Commit, then push a signed tag that matches the version:
git tag -s v1.0.0 -m v1.0.0 && git push origin v1.0.0. - The workflow:
- checks that the tag matches the package version,
- runs the test suite,
- builds the sdist and wheel,
- creates signed build provenance (Sigstore,
actions/attest-build-provenance), - publishes to PyPI with trusted publishing (PyPI adds its own digital attestations),
- creates a GitHub release with the artifacts and the changelog section.
Verifying a release¶
gh attestation verify agentic_chaos_security-1.0.0-py3-none-any.whl --repo RicoKomenda/agentic-chaos
The GitHub Action is versioned by the same tags. Move the major tag (v1) after each release so that
uses: RicoKomenda/agentic-chaos@v1 picks it up.