S3.4 — CI and publishing: current actions, Trusted Publishing, Dependabot
Intent
Remove the drift that built up over a year of pinned and 'latest' versions, retire Node-20 actions, move every registry to tokenless Trusted Publishing, and remove the sed/sleep crate-publish path that failed in 0.7.0.
Acceptance criteria
The pypi.yml criterion below is out of date. The senior engineer's trial run on a temp copy showed two parts of it no longer match the tooling:
pypa/gh-action-pypi-publishis replaced by maturin's ownuv publish --trusted-publishing.- The
working-directoryhand edits are no longer needed.
Owner to decide whether to rewrite the criterion when S3.4 starts. Details are under "Findings carried in from S3.2" below.
Tasks
Findings carried in from S3.2 (2026-10-09)
A trial regeneration of pypi.yml with maturin 1.15 was run on a temp copy and passed. The file is saved at /tmp/pypi.regenerated.yml, which is ephemeral; regenerate if it is gone.
- Config moved to pyproject: CLI flags are deprecated. Add
[tool.maturin.generate-ci.github]withpytest = trueandtrusted-publishing = truetooxmpl-py/pyproject.toml. The publish step becomesuv publish --trusted-publishing always, andPYPI_API_TOKENdisappears. - AC drift (owner to decide): the generator's own Trusted Publishing path (
uv publish) replaces the AC'spypa/gh-action-pypi-publish. The AC's "hand edits (working-directory) preserved" is obsolete: the generator now passes--manifest-path oxmpl-py/Cargo.tomlitself. - Hand edits still needed after generating:
- restore triggers: tags + PRs to
main(generated: push to main/master + all PRs);name: pypi - bump actions maturin pins one major behind: checkout/setup-python/upload-artifact v6→v7, download-artifact v7→v8, setup-uv v7→v10 (
attest@v4current) - regenerate with
-o .github/workflows/pypi.ymlso the header comment records the right command
- restore triggers: tags + PRs to
- Verified locally: actionlint clean; wheel job args build; sdist builds and rebuilds standalone; the generated pytest step passes 34/34. Not run on Actions.
- Risks:
- Emulated pytest (aarch64/s390x/ppc64le under QEMU) may be slow; drop it on those targets if CI time hurts.
- The module is pinned
gil_used = true(S3.2). Check that--find-interpreterdoes not ship untestedcp313twheels.
Source
Agreed in the senior-engineer grilling session 2026-10-08 (decisions in repo docs/planning/adr/0003-motion-validation.md, glossary in CONTEXT.md; toolchain research briefs in the same session).