diff --git a/.github/workflows/build_and_package.yml b/.github/workflows/build_and_package.yml index 7cd6d34b..9f17fd9b 100644 --- a/.github/workflows/build_and_package.yml +++ b/.github/workflows/build_and_package.yml @@ -14,6 +14,7 @@ on: env: MAIN_PYTHON_VERSION: "3.11" POETRY_VERSION: "2.3.2" + PACKAGE_NAME: "VISOR" # For Solutions private PyPI: POETRY_HTTP_BASIC_SOLUTIONS_PRIVATE_PYPI_USERNAME: "PAT" @@ -77,6 +78,10 @@ jobs: (needs.update-changelog.result == 'success' || needs.update-changelog.result == 'skipped') && (github.event_name != 'schedule' || github.ref == 'refs/heads/main') runs-on: ubuntu-latest + permissions: + id-token: write # Required for PyPI trusted publisher authentication (OIDC) + attestations: write # Required by pypa/gh-action-pypi-publish (>=v1.11) + contents: write # Needed to download release artifacts steps: - name: Checkout repository uses: actions/checkout@v4 @@ -266,7 +271,9 @@ jobs: path: dist/*.whl - name: Release to Azure Solutions PyPI - if : (github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')) + if: | + (github.event_name == 'schedule' && github.ref == 'refs/heads/main') || + (github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')) uses: ansys-internal/solution-applications-actions/release-to-private-pypi@v18 with: python-version: ${{ env.MAIN_PYTHON_VERSION }} @@ -274,16 +281,14 @@ jobs: twine-username: "TOKEN" twine-password: ${{ secrets.SOLUTIONS_PRIVATE_PYPI_UPLOAD_TOKEN }} - - name: Release to Azure PyAnsys PyPI - if: | - (github.event_name == 'schedule' && github.ref == 'refs/heads/main') || - (github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')) - uses: ansys-internal/solution-applications-actions/release-to-private-pypi@v18 + - name: "Upload artifacts to PyPI" + if: (github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')) + uses: pypa/gh-action-pypi-publish@ba38be9e461d3875417946c167d0b5f3d385a247 # v1.14.1 with: - python-version: ${{ env.MAIN_PYTHON_VERSION }} - twine-repository-url: https://pkgs.dev.azure.com/pyansys/_packaging/ansys-solutions/pypi/upload/ - twine-username: "TOKEN" - twine-password: ${{ secrets.SOLUTIONS_PRIVATE_PYPI_ADMIN_TOKEN }} + repository-url: "https://upload.pypi.org/legacy/" + print-hash: true + packages-dir: ${{ env.PACKAGE_NAME }}-artifacts + skip-existing: false outputs: package_version: ${{ steps.set_package_version.outputs.package_version }} diff --git a/doc/changelog.d/11.maintenance.md b/doc/changelog.d/11.maintenance.md new file mode 100644 index 00000000..66931f78 --- /dev/null +++ b/doc/changelog.d/11.maintenance.md @@ -0,0 +1 @@ +Push releases to public PyPI