promptfoo-python release by @mldangelo-oai #65
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: release-please | |
| run-name: promptfoo-python release by @${{ github.actor }} | |
| concurrency: | |
| group: release-please-${{ github.ref }} | |
| cancel-in-progress: false | |
| on: | |
| push: | |
| branches: | |
| - main | |
| pull_request: | |
| paths: | |
| - ".github/workflows/release-please.yml" | |
| - "release-please-config.json" | |
| workflow_dispatch: | |
| inputs: | |
| tag: | |
| description: "Release tag to re-publish (e.g. promptfoo-v0.1.3). Use when a release build failed." | |
| required: true | |
| type: string | |
| jobs: | |
| release-please: | |
| if: github.event_name != 'pull_request' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| outputs: | |
| release_created: ${{ steps.release.outputs.release_created }} | |
| tag_name: ${{ inputs.tag || steps.release.outputs.tag_name }} | |
| steps: | |
| # Only run the bot on push events; skip it for manual re-publish triggers. | |
| - uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5 | |
| id: release | |
| if: github.event_name == 'push' | |
| with: | |
| # A dedicated token lets the resulting pull_request run start without manual workflow approval. | |
| token: ${{ secrets.RELEASE_PLEASE_TOKEN || github.token }} | |
| build: | |
| if: | | |
| !cancelled() && | |
| (github.event_name == 'pull_request' || | |
| (needs.release-please.result == 'success' && | |
| (inputs.tag != '' || needs.release-please.outputs.release_created == 'true'))) | |
| needs: release-please | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| defaults: | |
| run: | |
| working-directory: package-source | |
| steps: | |
| - name: Check out publishing tool requirements from the workflow revision | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| with: | |
| ref: ${{ github.workflow_sha }} | |
| path: publishing-tools | |
| persist-credentials: false | |
| sparse-checkout: .github/requirements-twine.txt | |
| sparse-checkout-cone-mode: false | |
| - name: Save publishing tool requirements for historical tags | |
| working-directory: ${{ github.workspace }} | |
| run: cp publishing-tools/.github/requirements-twine.txt "$RUNNER_TEMP/requirements-twine.txt" | |
| - name: Check out the package source | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 | |
| with: | |
| ref: ${{ github.event_name == 'pull_request' && github.sha || needs.release-please.outputs.tag_name }} | |
| path: package-source | |
| persist-credentials: false | |
| - name: Verify the package source and publishing tool requirements are available | |
| run: | | |
| test -f pyproject.toml | |
| test -f "$RUNNER_TEMP/requirements-twine.txt" | |
| - uses: astral-sh/setup-uv@bec219d24cd3e171d82865faccec33120bb574f4 # v10.1.0 | |
| with: | |
| version: "0.12.17" | |
| enable-cache: auto | |
| working-directory: package-source | |
| - name: Pin Python version | |
| run: uv python pin 3.12 | |
| - name: Install dependencies | |
| env: | |
| REPUBLISH_TAG: ${{ inputs.tag }} | |
| run: | | |
| if [[ -n "$REPUBLISH_TAG" ]]; then | |
| # Historical tags predate keeping the package version in uv.lock in sync. | |
| uv sync --extra dev | |
| else | |
| uv sync --locked --extra dev | |
| fi | |
| - name: Run unit tests | |
| run: uv run pytest -m 'not smoke' -q | |
| - name: Build package | |
| run: uv build | |
| - name: Check distribution metadata with Twine | |
| run: uvx --from twine --constraints "$RUNNER_TEMP/requirements-twine.txt" twine check --strict dist/* | |
| - name: Verify package version matches release tag | |
| if: github.event_name != 'pull_request' | |
| env: | |
| TAG: ${{ needs.release-please.outputs.tag_name }} | |
| run: | | |
| EXPECTED_VERSION="${TAG#promptfoo-v}" | |
| if compgen -G "dist/*-${EXPECTED_VERSION}-*.whl" > /dev/null; then | |
| echo "✓ Package version ${EXPECTED_VERSION} matches release tag ${TAG}" | |
| else | |
| echo "ERROR: Package version mismatch!" | |
| echo "Expected: ${EXPECTED_VERSION} (from tag: ${TAG})" | |
| echo "Built packages:" | |
| ls -la dist/ | |
| exit 1 | |
| fi | |
| - name: Upload build artifacts | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 | |
| with: | |
| name: dist | |
| path: package-source/dist/ | |
| if-no-files-found: error | |
| publish-pypi: | |
| if: | | |
| github.event_name != 'pull_request' && | |
| (inputs.tag != '' || needs.release-please.outputs.release_created == 'true') | |
| needs: [build, release-please] | |
| runs-on: ubuntu-latest | |
| environment: | |
| name: pypi | |
| url: https://pypi.org/project/promptfoo/ | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - name: Download build artifacts | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8 | |
| with: | |
| name: dist | |
| path: dist/ | |
| - name: Publish to PyPI | |
| uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1 | |
| with: | |
| print-hash: true | |
| validate-action: | |
| name: Validate release-please action (read-only) | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Start the same release action without creating releases or pull requests | |
| uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5 | |
| with: | |
| skip-github-release: true | |
| skip-github-pull-request: true |