This project publishes to PyPI as keba-modbus-client via GitHub Actions using PyPI Trusted Publishing (OIDC) — no API tokens are stored as secrets.
In the repository settings (Settings > Environments), create two environments:
pypitestpypi
No secrets are needed in either — trusted publishing uses GitHub's OIDC token instead. You can optionally add required reviewers to the pypi environment as a manual approval gate before a real release goes out.
Since keba-modbus-client does not exist on PyPI yet, register a pending trusted publisher (this reserves the name for the first publish):
- Go to https://pypi.org/manage/account/publishing/.
- Under "Add a pending publisher", fill in:
- PyPI project name:
keba-modbus-client - Owner:
senfomat - Repository name:
PythonKebaClient - Workflow name:
publish.yml - Environment name:
pypi
- PyPI project name:
- Repeat on https://test.pypi.org/manage/account/publishing/ with environment name
testpypi, for test releases.
After the first successful publish, PyPI converts the pending publisher into a regular one automatically — nothing further to do.
-
Bump
versioninpyproject.toml(follow SemVer). -
Run the full check suite locally:
uv sync --all-extras --all-groups uv run pytest uvx ruff format --check . uvx ruff check . uvx ty check .
-
Commit the version bump and push to
main. -
Create a GitHub Release for the new version (
Releases > Draft a new release, tag it e.g.v0.2.0). -
Publishing the release triggers
.github/workflows/publish.yml, which builds the sdist/wheel withuv buildand uploads them to PyPI viauv publish --trusted-publishing always.
Before a real release (or to test the workflow itself), trigger it manually without cutting a GitHub Release:
Actions > Publish to PyPI > Run workflow, target = testpypi.
This builds and publishes the current main branch to https://test.pypi.org/project/keba-modbus-client/. Install it from there to sanity-check:
uv pip install --index-url https://test.pypi.org/simple/ --extra-index-url https://pypi.org/simple/ keba-modbus-client(The --extra-index-url is needed because TestPyPI does not mirror dependencies like pymodbus or pydantic.)
If you ever need to publish from your own machine instead of CI, use a PyPI API token instead of trusted publishing (which only works from the registered GitHub Actions workflow):
uv build
uv publish --token <your-pypi-api-token>Generate a scoped token at https://pypi.org/manage/account/token/.