Skip to content

feat(package): PyPI packaging standardization and automated OIDC release workflow - #19

Merged
MichalRedm merged 5 commits into
mainfrom
feat/10-pypi-packaging-oidc-release
Oct 6, 2026
Merged

MichalRedm merged 5 commits into
mainfrom
feat/10-pypi-packaging-oidc-release

Conversation

@MichalRedm

Copy link
Copy Markdown
Collaborator

Summary

  • Dynamic Single-Source Versioning: Configured dynamic = ["version"] in pyproject.toml targeting src/stride/__init__.py as the authoritative source of truth.
  • PyPI Discoverability & Metadata: Added comprehensive keywords and populated [project.urls] navigation tables (Homepage, Documentation, Repository, Issues, Changelog).
  • PyPI-Safe Assets & Readme Updates: Replaced relative image and license references in README.md with absolute URLs to ensure correct rendering on pypi.org, and added PyPI badges along with PyPI quickstart installation instructions.
  • Keep a Changelog Baseline: Introduced CHANGELOG.md following Semantic Versioning and Keep a Changelog specifications for release 0.1.0.
  • Automated OIDC Release Workflow: Created .github/workflows/release.yml for PyPI and TestPyPI publishing via OpenID Connect (OIDC) Trusted Publishing (pypa/gh-action-pypi-publish), including automated distribution build verification via twine check --strict and a TestPyPI smoke testing job.

Motivation

Prepares STRIDE for public release on the Python Package Index (PyPI) under the package name stride-xai, establishing reproducible build validation and credential-free OIDC publishing automation. Resolves #10.

Key Changes

1. Packaging & Metadata (pyproject.toml)

  • Switched version to dynamic configuration (dynamic = ["version"]).
  • Added package navigation URLs ([project.urls]) and search keywords.
  • Added build and twine to [project.optional-dependencies] dev.

2. Documentation & Assets (README.md, CHANGELOG.md)

  • Converted assets/pipeline.png to an absolute raw GitHub URL.
  • Converted license links to absolute GitHub URLs.
  • Added PyPI version and supported Python version badges.
  • Documented pip install stride-xai and optional extras in the Installation section.
  • Added structured CHANGELOG.md documenting features for version 0.1.0.

3. CI/CD Release Automation (.github/workflows/release.yml)

  • Trigger on published GitHub Releases and manual dispatch (workflow_dispatch).
  • Build sdist and wheel with PEP 517 build backend.
  • Validate metadata and long description with twine check --strict.
  • OIDC Trusted Publishing integration via pypa/gh-action-pypi-publish@release/v1 for both testpypi and pypi environments.
  • Isolated container smoke test for TestPyPI installations.

4. Agent Context Maintenance (.agents/project_context.md)

Verification

  • Distribution build (python -m build) succeeded with clean sdist and wheel artifacts containing src/stride/py.typed
  • twine check --strict dist/* passed with zero warnings or errors
  • ruff check . passed with 0 errors
  • ruff format --check . passed cleanly across 106 files
  • python -m unittest discover tests passed with 28 tests passing and 0 failures

@MichalRedm
MichalRedm merged commit e18ea7a into main Oct 6, 2026
1 check passed
@MichalRedm
MichalRedm deleted the feat/10-pypi-packaging-oidc-release branch October 6, 2026 21:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

release: PyPI Packaging, Metadata Standardization, and Automated OIDC Trusted Publishing Workflow

1 participant