Files
codex/.github/workflows/python-runtime-release.yml
Ahmed Ibrahim 26ce6649a2 Build Python SDK artifacts before publishing the runtime (#44061)
## Why

The SDK release workflow published the runtime before building the SDK, so an SDK build failure could leave the runtime published on its own.

## What changed

- Extract a reusable SDK build workflow that packages checked-in generated code and runs alongside runtime preparation. Require both builds before publishing the runtime, and verify runtime availability before publishing the SDK.
- Add `stage-sdk --codex-version` to set an explicit runtime dependency independently of the SDK version, retaining the checked-in pin by default and rejecting missing or duplicate pins.
- Accept Codex release tags in the runtime version resolver and use its normalized Python version for standalone runtime PyPI verification.

## Testing

Add coverage for wheel and source distribution metadata, preservation of checked-in code, independent beta SDK versions, runtime tag normalization, and invalid versions or dependency pins.

GitOrigin-RevId: feb572fadcf5d148814b26b480b4bae5ef6a39c5
2026-09-09 05:14:27 +00:00

64 lines
2.0 KiB
YAML

name: python-runtime-release
on:
workflow_dispatch:
inputs:
runtime_version:
description: "Runtime version to publish before updating the SDK pin, for example 0.136.0, 0.136.0a2, or 0.136.0a2.post1."
required: true
type: string
concurrency:
group: python-runtime-release-${{ inputs.runtime_version }}
cancel-in-progress: false
jobs:
prepare-python-runtime:
name: prepare-python-runtime
permissions:
contents: read
uses: ./.github/workflows/python-runtime-build.yml
with:
runtime_version: ${{ inputs.runtime_version }}
# PyPI must trust this top-level workflow for manual runtime publication.
publish-python-runtime:
if: github.repository == 'openai/codex'
name: publish-python-runtime
needs: prepare-python-runtime
runs-on: ubuntu-latest
environment: pypi
permissions:
contents: read
id-token: write # Required for PyPI trusted publishing.
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Download Python runtime wheels
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: python-runtime-wheels
path: dist/python-runtime
- name: Publish Python runtime wheels to PyPI
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2
with:
packages-dir: dist/python-runtime
skip-existing: true
- name: Install uv
uses: astral-sh/setup-uv@08807647e7069bb48b6ef5acd8ec9567f424441b # v8.1.0
with:
version: "0.11.3"
- name: Verify Python runtime wheels are available on PyPI
env:
PYTHON_RUNTIME_VERSION: ${{ needs.prepare-python-runtime.outputs.python_version }}
run: |
uv run --no-project --with packaging==26.2 python .github/scripts/verify_pypi_release.py \
openai-codex-cli-bin "$PYTHON_RUNTIME_VERSION"