Skip to content

ci: Tag every merge to main, publish on GitHub release - #3

Merged
HQJaTu merged 3 commits into
mainfrom
ci/auto-release
Sep 29, 2026
Merged

HQJaTu merged 3 commits into
mainfrom
ci/auto-release

Conversation

@HQJaTu

@HQJaTu HQJaTu commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

What

Every pull request merged to main gets a version tag automatically. Publishing to PyPI starts when someone publishes a GitHub release on that tag.

  1. Tag (.github/workflows/tag.yml, new; runs on pull_request_target: closed): tags the merge commit with the next version.

    Label Step
    none patch, 1.2.3 → 1.2.4
    minor-version minor, 1.2.3 → 1.3.0
    major-version major, 1.2.3 → 2.0.0

    If no v* tag exists yet, it creates v1.0.0. Tagging alone publishes nothing.

  2. Publish (publish.yml; runs on release: published): when a user publishes a GitHub release on a v* tag, it builds that tag, publishes to PyPI, and attaches the wheel and the sdist to the release. Running it by hand on a branch still publishes a .devN version to TestPyPI. Pushing a tag no longer publishes, and PyPI is reached only from a release event.

Details

  • Where the version comes from: the tag, through setuptools-scm (dynamic = ["version"], local_scheme = "no-local-version"). pyproject.toml no longer holds a version, so no "bump" commit to main is needed. Publish checks that the built version matches the tag.
  • The Tag workflow never checks out or runs pull request code. It reads only the labels and the merge commit, through the API.
  • Merges tag one at a time, because of concurrency. A merge commit that is already tagged is refused.
  • fetch-depth: 0 is now set on the checkouts in ci.yml and publish.yml, so setuptools-scm can see the tags.
  • Trusted Publisher unchanged: it still points at the workflow publish.yml.

Needed before merging

  • The release tags ruleset must not have "Restrict creations": GITHUB_TOKEN can't be a ruleset bypass actor (422: "must be part of the ruleset source or owner organization"). Moving and deleting v* tags stays admin-only, and a tag alone publishes nothing.
  • Before publishing the v1.0.0 release, add a pending publisher on pypi.org for mfiles-grpc: owner M-Files, repository mfiles-grpc-python, workflow publish.yml, no environment.

Tested locally

  • A build from a clone without a tag gives mfiles_grpc-0.1.dev5. With a v1.0.0 tag it gives mfiles_grpc-1.0.0, and the wheel holds no .proto.
  • The version script gives the expected result for:
    • no tags;
    • each label on its own;
    • both labels (major wins);
    • v1.9.9 against v1.10.0 (compared as numbers);
    • an already-tagged merge commit (refused).

🤖 Generated with Claude Code

HQJaTu and others added 2 commits September 29, 2026 21:57
Merging a pull request to main tags the merge commit with the next version
(patch by default; minor-version or major-version labels bump more) and
starts Publish on that tag, which publishes to PyPI and creates the GitHub
release. The first tag is v1.0.0.

The version now comes from the tag through setuptools-scm, so
pyproject.toml no longer holds one.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Tag only tags the merge commit. Publishing a GitHub release on a v* tag
starts Publish, which publishes to PyPI and attaches the wheel and sdist
to that release. Pushing a tag no longer publishes, and running Publish
by hand on a tag no longer reaches PyPI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@HQJaTu HQJaTu changed the title ci: Tag and release every merge to main ci: Tag every merge to main, publish on GitHub release Sep 29, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@HQJaTu
HQJaTu merged commit f43b244 into main Sep 29, 2026
5 checks passed
@HQJaTu
HQJaTu deleted the ci/auto-release branch September 29, 2026 19:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant