From 329863bc87d7820dd63b81b921b14ce1c8c69ca4 Mon Sep 17 00:00:00 2001 From: Abas-Tim <8209950+Abas-Tim@users.noreply.github.com> Date: Fri, 28 Aug 2026 12:11:18 -0700 Subject: [PATCH 1/2] fix: simplify dev-publish workflow, move skip logic into script --- .github/workflows/dev-publish.yml | 14 +++++++++----- scripts/dev_version.py | 9 ++++++++- 2 files changed, 17 insertions(+), 6 deletions(-) diff --git a/.github/workflows/dev-publish.yml b/.github/workflows/dev-publish.yml index d83b925..aed21ce 100644 --- a/.github/workflows/dev-publish.yml +++ b/.github/workflows/dev-publish.yml @@ -2,12 +2,16 @@ name: dev-publish on: push: - branches: [main] + branches: + - main workflow_dispatch: + inputs: + dry_run: + description: "skip the PyPI upload (validation run)" + required: false jobs: dev: - if: ${{ github.event_name != 'push' || !contains(github.event.head_commit.message, 'chore(release)') }} runs-on: ubuntu-latest permissions: contents: read @@ -20,6 +24,8 @@ jobs: enable-cache: false - name: Derive dev version id: ver + env: + HEAD_MESSAGE: ${{ github.event.head_commit.message }} run: | VER=$(python scripts/dev_version.py | tail -n1) echo "version=$VER" >> "$GITHUB_OUTPUT" @@ -27,9 +33,7 @@ jobs: if: ${{ !startsWith(steps.ver.outputs.version, 'SKIP') }} run: uv build - name: Publish to PyPI - if: ${{ !startsWith(steps.ver.outputs.version, 'SKIP') }} + if: ${{ !startsWith(steps.ver.outputs.version, 'SKIP') && github.event.inputs.dry_run != 'true' }} env: UV_PUBLISH_TOKEN: ${{ secrets.PYPI_TOKEN }} run: uv publish - - name: Log published version - run: echo "urag-cli pre-release: ${{ steps.ver.outputs.version }}" diff --git a/scripts/dev_version.py b/scripts/dev_version.py index a6e54d7..c208be8 100644 --- a/scripts/dev_version.py +++ b/scripts/dev_version.py @@ -4,13 +4,15 @@ Example: latest stable tag v0.2.0, 3 commits on main -> 0.2.1.dev3. Prints the version to stdout, or "SKIP" (details on stderr) when there is -nothing to publish (no stable tags yet, or HEAD is a tagged commit). +nothing to publish (no stable tags yet, HEAD is a tagged commit, or the +HEAD commit is a release-prep commit). Side effects: rewrites the `version` line in pyproject.toml and `__version__` in src/urag/__init__.py so the built artifacts carry the derived version. Intended for CI runners only. """ +import os import re import subprocess import sys @@ -38,6 +40,11 @@ def skip(reason: str) -> None: print("SKIP") +head_message = os.environ.get("HEAD_MESSAGE") or git("log", "-1", "--pretty=%s") +if "chore(release)" in head_message: + skip("release-prep commit; stable tag flow publishes it") + raise SystemExit(0) + tags = git("tag", "--list", "v[0-9]*").splitlines() stable = [t[1:] for t in tags if STABLE_TAG.match(t)] if not stable: From 4102d4e9e2f66058bfa51815aa0c4ae2de21aaf2 Mon Sep 17 00:00:00 2001 From: Abas-Tim <8209950+Abas-Tim@users.noreply.github.com> Date: Fri, 28 Aug 2026 12:13:58 -0700 Subject: [PATCH 2/2] fix: guard dev-publish to main refs only --- .github/workflows/dev-publish.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/dev-publish.yml b/.github/workflows/dev-publish.yml index aed21ce..a82e65a 100644 --- a/.github/workflows/dev-publish.yml +++ b/.github/workflows/dev-publish.yml @@ -27,6 +27,11 @@ jobs: env: HEAD_MESSAGE: ${{ github.event.head_commit.message }} run: | + if [[ "$GITHUB_EVENT_NAME" == "push" && "$GITHUB_REF" != "refs/heads/main" ]]; then + echo "SKIP: dev releases only publish from main" >&2 + echo "version=SKIP" >> "$GITHUB_OUTPUT" + exit 0 + fi VER=$(python scripts/dev_version.py | tail -n1) echo "version=$VER" >> "$GITHUB_OUTPUT" - name: Build wheel + sdist