@@ -17,15 +17,15 @@ backward-compatible fixes.
1717
1818## Release checklist
1919
20- 1 . ** Green main** — ` pytest ` , ` ruff check . ` , ` mypy src/freshdata ` , and
20+ 1 . ** Green main** — ` pytest -m "not online and not large" ` , ` ruff check . ` , ` mypy src/freshdata ` , and
2121 ` mkdocs build --strict ` all pass.
22222 . ** Bump the version** in ` pyproject.toml ` and ` src/freshdata/__init__.py ` .
23233 . ** Update ` CHANGELOG.md ` ** — move ` Unreleased ` notes under a new
2424 ` ## [X.Y.Z] - YYYY-MM-DD ` heading.
25254 . ** Commit & PR** — merge to ` main ` .
26265 . ** Build & validate** locally (see below).
27276 . ** Publish to TestPyPI** , smoke-test the install.
28- 7 . ** Publish to PyPI** (or push the tag and let CI do it).
28+ 7 . ** Publish to PyPI** (push the tag and let CI do it through trusted publishing ).
29298 . ** Tag & GitHub release** — ` git tag vX.Y.Z ` and create the release with
3030 notes from the changelog.
31319 . ** Verify** — ` pip install freshdata-cleaner ` in a clean environment imports
@@ -42,10 +42,11 @@ twine check dist/* # validates metadata + long-description renderin
4242
4343## Publish
4444
45- ### Option A — automated (recommended )
45+ ### Option A — automated (required )
4646
47- Push a version tag; the ` Release ` workflow builds and publishes via PyPI
48- ** Trusted Publishing** (OIDC, no stored token):
47+ Push a version tag; the ` Release ` workflow runs a quality gate first
48+ (lint, typecheck, ` pytest -m "not online and not large" ` , docs strict),
49+ then builds and publishes via PyPI ** Trusted Publishing** (OIDC, no stored token):
4950
5051``` bash
5152git tag v0.5.0
@@ -56,7 +57,7 @@ One-time setup: add a trusted publisher at
5657< https://pypi.org/manage/project/freshdata-cleaner/settings/publishing/ >
5758(workflow ` release.yml ` , environment ` pypi ` ).
5859
59- ### Option B — manual with ` twine `
60+ ### Option B — manual with ` twine ` (fallback only)
6061
6162``` bash
6263# 1. TestPyPI first
@@ -69,8 +70,9 @@ python -c "import freshdata as fd; print(fd.__version__)"
6970twine upload dist/*
7071```
7172
72- Use a [ PyPI API token] ( https://pypi.org/help/#apitoken ) (username ` __token__ ` ).
73- Never commit tokens; prefer ` ~/.pypirc ` or the ` TWINE_PASSWORD ` env var.
73+ Use a [ PyPI API token] ( https://pypi.org/help/#apitoken ) (username ` __token__ ` ) only
74+ for emergency/manual fallback releases. Never commit tokens; prefer ` ~/.pypirc `
75+ or the ` TWINE_PASSWORD ` env var.
7476
7577## Naming
7678
0 commit comments