Skip to content

chore(ci): make PyPI publish manual-only - #83

Merged
noel merged 1 commit into
mainfrom
chore/manual-only-pypi-publish
Sep 28, 2026
Merged

noel merged 1 commit into
mainfrom
chore/manual-only-pypi-publish

Conversation

@noel

@noel noel commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

What

Drop the release: types: [published] trigger from release-package.yml, leaving workflow_dispatch as the only way to publish to PyPI.

Why

Publishing is done by hand — 30 of the last 39 runs of this workflow were manual workflow_dispatch, only 9 fired via release: published. Since the automatic path isn't relied on, there's no reason for bump-version.yml's release-creation step to also need to count as an external actor (the whole point of #80's GitHub App token). This removes that requirement entirely rather than continuing to chase getting it right (see the closed #82).

PyPI publishing is done by hand via workflow_dispatch, not via the
release: published trigger -- 30 of the last 39 runs were manual, and the
maintainer doesn't rely on the automatic path. Dropping the event trigger
removes the ambiguity around whether creating a release in bump-version.yml
needs to count as an external actor.
@github-actions

Copy link
Copy Markdown

Review of PR #83

No issues found.

The diff removes the release: published trigger from .github/workflows/release-package.yml, so the workflow now runs only on workflow_dispatch. This matches the PR's stated intent. It touches no resource, blueprint, SQL or lifecycle code, and no credential literals are added. The secrets still come from secrets.*.

Publishing to PyPI will no longer happen automatically when a GitHub release is published. Someone has to run the workflow by hand as part of each release.

@noel
noel merged commit 666d89b into main Sep 28, 2026
6 checks passed
@noel
noel deleted the chore/manual-only-pypi-publish branch September 28, 2026 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant