Skip to content

promptfoo-python release by @mldangelo-oai #65

promptfoo-python release by @mldangelo-oai

promptfoo-python release by @mldangelo-oai #65

name: release-please
run-name: promptfoo-python release by @${{ github.actor }}
concurrency:
group: release-please-${{ github.ref }}
cancel-in-progress: false
on:
push:
branches:
- main
pull_request:
paths:
- ".github/workflows/release-please.yml"
- "release-please-config.json"
workflow_dispatch:
inputs:
tag:
description: "Release tag to re-publish (e.g. promptfoo-v0.1.3). Use when a release build failed."
required: true
type: string
jobs:
release-please:
if: github.event_name != 'pull_request'
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
outputs:
release_created: ${{ steps.release.outputs.release_created }}
tag_name: ${{ inputs.tag || steps.release.outputs.tag_name }}
steps:
# Only run the bot on push events; skip it for manual re-publish triggers.
- uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5
id: release
if: github.event_name == 'push'
with:
# A dedicated token lets the resulting pull_request run start without manual workflow approval.
token: ${{ secrets.RELEASE_PLEASE_TOKEN || github.token }}
build:
if: |
!cancelled() &&
(github.event_name == 'pull_request' ||
(needs.release-please.result == 'success' &&
(inputs.tag != '' || needs.release-please.outputs.release_created == 'true')))
needs: release-please
runs-on: ubuntu-latest
permissions:
contents: read
defaults:
run:
working-directory: package-source
steps:
- name: Check out publishing tool requirements from the workflow revision
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
ref: ${{ github.workflow_sha }}
path: publishing-tools
persist-credentials: false
sparse-checkout: .github/requirements-twine.txt
sparse-checkout-cone-mode: false
- name: Save publishing tool requirements for historical tags
working-directory: ${{ github.workspace }}
run: cp publishing-tools/.github/requirements-twine.txt "$RUNNER_TEMP/requirements-twine.txt"
- name: Check out the package source
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
with:
ref: ${{ github.event_name == 'pull_request' && github.sha || needs.release-please.outputs.tag_name }}
path: package-source
persist-credentials: false
- name: Verify the package source and publishing tool requirements are available
run: |
test -f pyproject.toml
test -f "$RUNNER_TEMP/requirements-twine.txt"
- uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0
with:
version: "0.12.17"
enable-cache: auto
working-directory: package-source
- name: Pin Python version
run: uv python pin 3.12
- name: Install dependencies
env:
REPUBLISH_TAG: ${{ inputs.tag }}
run: |
if [[ -n "$REPUBLISH_TAG" ]]; then
# Historical tags predate keeping the package version in uv.lock in sync.
uv sync --extra dev
else
uv sync --locked --extra dev
fi
- name: Run unit tests
run: uv run pytest -m 'not smoke' -q
- name: Build package
run: uv build
- name: Check distribution metadata with Twine
run: uvx --from twine --constraints "$RUNNER_TEMP/requirements-twine.txt" twine check --strict dist/*
- name: Verify package version matches release tag
if: github.event_name != 'pull_request'
env:
TAG: ${{ needs.release-please.outputs.tag_name }}
run: |
EXPECTED_VERSION="${TAG#promptfoo-v}"
if compgen -G "dist/*-${EXPECTED_VERSION}-*.whl" > /dev/null; then
echo "✓ Package version ${EXPECTED_VERSION} matches release tag ${TAG}"
else
echo "ERROR: Package version mismatch!"
echo "Expected: ${EXPECTED_VERSION} (from tag: ${TAG})"
echo "Built packages:"
ls -la dist/
exit 1
fi
- name: Upload build artifacts
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: dist
path: package-source/dist/
if-no-files-found: error
publish-pypi:
if: |
github.event_name != 'pull_request' &&
(inputs.tag != '' || needs.release-please.outputs.release_created == 'true')
needs: [build, release-please]
runs-on: ubuntu-latest
environment:
name: pypi
url: https://pypi.org/project/promptfoo/
permissions:
contents: read
id-token: write
steps:
- name: Download build artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
name: dist
path: dist/
- name: Publish to PyPI
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1
with:
print-hash: true
validate-action:
name: Validate release-please action (read-only)
if: github.event_name == 'pull_request'
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
steps:
- name: Start the same release action without creating releases or pull requests
uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5
with:
skip-github-release: true
skip-github-pull-request: true