From f2d0b004e702beb67ba03e98531f901f5e071bf9 Mon Sep 17 00:00:00 2001 From: jrobinAV Date: Thu, 29 Feb 2024 10:30:49 +0100 Subject: [PATCH] Add permission for dev release action to publish on Pypi --- .github/workflows/build-and-release-dev.yml | 2 ++ .github/workflows/publish.yml | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build-and-release-dev.yml b/.github/workflows/build-and-release-dev.yml index 10b365e712..3f578b7304 100644 --- a/.github/workflows/build-and-release-dev.yml +++ b/.github/workflows/build-and-release-dev.yml @@ -122,6 +122,8 @@ jobs: uses: pypa/gh-action-pypi-publish@release/v1 build-and-release-taipy-dev: + permissions: + id-token: write # IMPORTANT: this permission is mandatory for trusted publishing runs-on: ubuntu-latest needs: [ build-and-release-taipy-dev-packages, fetch-versions ] timeout-minutes: 20 diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 5a41733d97..27a75cdfce 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -48,7 +48,7 @@ jobs: sparse-checkout: taipy/${{ matrix.package }} sparse-checkout-cone-mode: false - - name: Checks if package is already on on Pypi + - name: Checks if package is already on Pypi id: check-version run: | if curl https://pypi.org/simple/taipy-${{ matrix.package }} | grep -o ">taipy-${{ matrix.package }}-${{ github.event.inputs.version }}\.tar\.gz<"; then