Two one-time human steps before the tag-triggered publish workflow (PR #3) can be used.
1. Register a Trusted Publisher on PyPI
On pypi.org → the algosystem project → Settings → Publishing → add a GitHub Trusted Publisher for this repo + the publish-pypi.yml workflow filename. Until then the publish step fails with an authentication error.
This uses OIDC, so no long-lived API token needs to be stored as a repo secret.
2. Bump the version first
algosystem is already on PyPI at 0.1.9 (10 releases, published manually) — but pyproject.toml on main still says version = "0.1.7". Confirmed via the PyPI JSON API; poetry build locally currently produces a 0.1.7 artifact.
PyPI rejects re-uploading an existing version, so [tool.poetry].version must be bumped past 0.1.9 before pushing a matching v* tag.
Blocked on: PR #3.
Two one-time human steps before the tag-triggered publish workflow (PR #3) can be used.
1. Register a Trusted Publisher on PyPI
On pypi.org → the
algosystemproject → Settings → Publishing → add a GitHub Trusted Publisher for this repo + thepublish-pypi.ymlworkflow filename. Until then the publish step fails with an authentication error.This uses OIDC, so no long-lived API token needs to be stored as a repo secret.
2. Bump the version first
algosystemis already on PyPI at 0.1.9 (10 releases, published manually) — butpyproject.tomlonmainstill saysversion = "0.1.7". Confirmed via the PyPI JSON API;poetry buildlocally currently produces a0.1.7artifact.PyPI rejects re-uploading an existing version, so
[tool.poetry].versionmust be bumped past0.1.9before pushing a matchingv*tag.Blocked on: PR #3.