Skip to content

fix(ci): make the PyPI publish workflow actually runnable - #537

Merged
MichaelGHSeg merged 1 commit into
masterfrom
ci/fix-publish-owner-guard
Sep 28, 2026
Merged

MichaelGHSeg merged 1 commit into
masterfrom
ci/fix-publish-owner-guard

Conversation

@MichaelGHSeg

Copy link
Copy Markdown
Contributor

The publish workflow has never run. Three independent blockers, each of which alone prevents a release:

Blocker Effect
if: github.repository_owner == 'twilio' on both jobs repo is under segmentio, so both jobs skip — the workflow reports success having published nothing
runs-on falls through to bare ubuntu-latest gets no runner in this org
tag regex requires a v prefix every tag in this repo is bare (2.3.6, 2.3.5, …)

The first two came from the twilio-agent-connect-typescript reference implementation, where the owner guard is correct.

The fork guard is kept, just pointed at the right owner.

RELEASING.md was also stale in a way that matters: it told you to run make release (a local twine upload that bypasses Trusted Publishing and provenance) and to publish by pushing a tag. on: release: [published] does not fire on a tag push — it needs a GitHub Release. It also omitted pyproject.toml, which is the file the workflow validates the tag against, so following it produced a version mismatch.

Not addressed here: make release still exists as a break-glass path, and the version lives in both pyproject.toml and segment/analytics/version.py.

Three things independently prevented a release:

- Both jobs were gated on `github.repository_owner == 'twilio'`, carried over
  from the reference implementation. This repo is under segmentio, so a
  published release skipped both jobs and reported success having uploaded
  nothing. The guard still blocks forks, just against the right owner.
- The runner expression fell through to bare ubuntu-latest, which gets no
  runner in this org.
- Tag validation required a v prefix; every tag here is bare (2.3.6, 2.3.5).
  Both forms are accepted now.

RELEASING.md described a local twine upload and a bare tag push. Neither
reaches the OIDC path, and `release: published` does not fire on a tag push at
all, so it now says to cut a GitHub Release and to bump pyproject.toml — which
is the file the tag is validated against.
@MichaelGHSeg
MichaelGHSeg merged commit 29e409e into master Sep 28, 2026
17 of 18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants