Skip to content

ci: Add PyPI publishing job. Improve release job structure and security. #23

ci: Add PyPI publishing job. Improve release job structure and security.

ci: Add PyPI publishing job. Improve release job structure and security. #23

Workflow file for this run

name: python-server-sdk
on:
push:
pull_request:
workflow_dispatch:
permissions:
contents: read
# The checks themselves live in the Makefile so that CI and the pre-push hook cannot drift
# apart. bash everywhere keeps the make recipes portable across the runner images.
defaults:
run:
shell: bash
jobs:
lint:
name: Lint + Typecheck
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v5
- name: Install uv
uses: astral-sh/setup-uv@v6
with:
enable-cache: true
- run: make verify-lock
- run: make lint
- run: make typecheck
test:
name: Test (Python ${{ matrix.python-version }} on ${{ matrix.os }})
runs-on: ${{ matrix.os }}
# Backstop only. pytest-timeout is what turns a wedged test into a failure with a
# thread dump; this bounds anything outside pytest, such as a dependency install.
timeout-minutes: 15
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest]
python-version: ["3.10", "3.11", "3.12", "3.13", "3.14"]
include:
- os: macos-latest
python-version: "3.13"
- os: windows-latest
python-version: "3.13"
steps:
- uses: actions/checkout@v5
- name: Install uv
uses: astral-sh/setup-uv@v6
with:
enable-cache: true
python-version: ${{ matrix.python-version }}
- run: make verify-lock
- run: make coverage
build:
name: Build distribution
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v5
- name: Install uv
uses: astral-sh/setup-uv@v6
with:
enable-cache: true
# Builds into dist/, checks the metadata, and imports the wheel in a clean environment.
- run: make dist-check
- uses: actions/upload-artifact@v4
with:
name: dist
path: dist/
samples:
name: Sample apps
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@v5
- name: Install uv
uses: astral-sh/setup-uv@v6
with:
enable-cache: true
# Each sample resolves the SDK by local path, so it is not locked against a release.
- run: make samples