chore(ci): fix ci serurity and add build wheels for test pypi (#16)

* fix(ci): add permissions for ci

* fix(ci): add build wheel for test pypi

* fix: remove unused  extra-index-url
This commit is contained in:
Cuiys 2026-01-09 10:37:48 +08:00 committed by GitHub
parent 84b5f03f5e
commit 5853493f87
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
5 changed files with 67 additions and 0 deletions

55
.github/workflows/build_test_wheel.yml vendored Normal file
View File

@ -0,0 +1,55 @@
name: Build Test PyPi Wheels
on:
workflow_dispatch:
permissions:
contents: read
jobs:
build_wheels:
name: Build wheels on self-hosted manylinux_2_28
runs-on: linux_x64
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
submodules: recursive
- name: Set up Python (for cibuildwheel controller)
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Install cibuildwheel
run: |
pip install --upgrade pip
pip install cibuildwheel==2.17.0
- name: Build wheels using cibuildwheel
run: |
python -m cibuildwheel --output-dir wheelhouse
# Save list of built wheels for publishing
ls wheelhouse/*.whl | tee $GITHUB_STEP_SUMMARY
echo "wheels=$(ls wheelhouse/*.whl | tr '\n' ' ')" >> $GITHUB_ENV
- name: Publish to TestPyPI
if: success() && github.event_name == 'workflow_dispatch'
env:
TWINE_USERNAME: __token__
TWINE_PASSWORD: ${{ secrets.TEST_PYPI_API_TOKEN }}
TWINE_REPOSITORY_URL: https://test.pypi.org/legacy/
run: |
pip install twine
twine upload --skip-existing --verbose wheelhouse/*.whl
- name: (Optional) Install and test from TestPyPI
if: success() && github.event_name == 'workflow_dispatch'
run: |
# Create a clean venv
python -m venv test_env
source test_env/bin/activate
pip install --upgrade pip
# Install from TestPyPI (must allow pre-releases if version has dev/alpha)
pip install --index-url https://test.pypi.org/simple/ zvec
# Run a simple smoke test
python -c "import zvec; print('Import OK:', zvec.__version__)"
shell: bash

View File

@ -3,6 +3,9 @@ name: Build Wheels
on:
workflow_dispatch:
permissions:
contents: read
jobs:
build_wheels:
name: Build wheels on self-hosted manylinux_2_28

View File

@ -7,6 +7,9 @@ on:
branches: [ "main" ]
workflow_dispatch:
permissions:
contents: read
jobs:
build:
runs-on: linux_x64

View File

@ -7,6 +7,9 @@ on:
branches: [ "main" ]
workflow_dispatch:
permissions:
contents: read
jobs:
build:
runs-on: mac_m1_arm

View File

@ -7,6 +7,9 @@ on:
workflow_dispatch:
permissions:
contents: read
jobs:
coverage:
runs-on: linux_x64