S3.4 — CI and publishing: current actions, Trusted Publishing, Dependabot

Intent

Remove the drift that built up over a year of pinned and 'latest' versions, retire Node-20 actions, move every registry to tokenless Trusted Publishing, and remove the sed/sleep crate-publish path that failed in 0.7.0.

Acceptance criteria

Revisit before starting (noted 2026-10-09)

The pypi.yml criterion below is out of date. The senior engineer's trial run on a temp copy showed two parts of it no longer match the tooling:

  • pypa/gh-action-pypi-publish is replaced by maturin's own uv publish --trusted-publishing.
  • The working-directory hand edits are no longer needed.

Owner to decide whether to rewrite the criterion when S3.4 starts. Details are under "Findings carried in from S3.2" below.

Tasks

Findings carried in from S3.2 (2026-10-09)

A trial regeneration of pypi.yml with maturin 1.15 was run on a temp copy and passed. The file is saved at /tmp/pypi.regenerated.yml, which is ephemeral; regenerate if it is gone.

Source

Agreed in the senior-engineer grilling session 2026-10-08 (decisions in repo docs/planning/adr/0003-motion-validation.md, glossary in CONTEXT.md; toolchain research briefs in the same session).