switch to Trusted Publishing OIDC, drop twine/setuptools pins, v0.1.4

Pending publisher registered on PyPI for python/erldistpy with
workflow filepath .gitlab-ci.yml — GitLab now mints a short-lived
OIDC ID token (audience=pypi) per pipeline, twine 6+ exchanges it
for a scoped upload token. No long-lived secret on the runner.

What this commit changes:
  - .gitlab-ci.yml pypi-twine stage gains id_tokens: PYPI_ID_TOKEN
  - pip install twine (no <6 pin) — twine 6 is OIDC-native
  - pyproject.toml build-system requires drops the setuptools<77 cap
    (latest setuptools emits Metadata-Version 2.4 which twine 6 reads
    fine; locally verified)

After this tag publishes successfully, the same pattern goes to:
  - ago (python/ago)
  - make-post-sell (engineering/make-post-sell)
  - remarkbox (engineering/remarkbox)
each gets a Trusted Publisher entry added on the PyPI project page,
then the id_tokens block lands in their CI.

Recipe lives at docs/PYPI-TRUSTED-PUBLISHING.md (updated to reflect
the new auth model is now live for erldistpy).
This commit is contained in:
russell@unturf.com 2026-06-16 14:54:53 -04:00
parent 08e89d5652
commit 049666b061
No known key found for this signature in database
3 changed files with 10 additions and 15 deletions

View file

@ -35,17 +35,17 @@ pypi-twine:
tags: ["build"]
only:
- tags
# GitLab mints a short-lived OIDC ID token (audience=pypi) and injects
# it as PYPI_ID_TOKEN. Twine v6+ auto-detects it and exchanges it with
# PyPI for a scoped upload token. No long-lived secret on the runner.
id_tokens:
PYPI_ID_TOKEN:
aud: pypi
script:
- python3 -m venv .venv
- . .venv/bin/activate
- pip install --upgrade pip
# Pin twine <6 — newer twine auto-detects GitLab CI and refuses to
# fall back to ~/.pypirc on the runner, requiring PYPI_ID_TOKEN
# (Trusted Publishing OIDC) instead. Until we migrate all four
# python/* repos to Trusted Publishing in one coordinated change,
# stick with the classic ~/.pypirc path that ago / make_post_sell /
# remarkbox already use.
- pip install build "twine<6"
- pip install build twine
- python -m build
- twine check dist/*
- twine upload --non-interactive dist/*