mirror of
https://github.com/langchain-ai/langchain.git
synced 2026-10-09 19:35:20 +03:00
Bumps the minor-and-patch group with 3 updates: [actions/checkout](https://github.com/actions/checkout), [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) and [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials). Updates `actions/checkout` from 7.0.0 to 7.0.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/actions/checkout/releases">actions/checkout's releases</a>.</em></p> <blockquote> <h2>v7.0.1</h2> <h2>What's Changed</h2> <ul> <li>skip running unsafe pr check if input is default by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li> <li>trim only ascii whitespace for branch by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li> <li>escape values passed to --unset by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li> <li>Various dependency updates</li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/actions/checkout/compare/v7...v7.0.1">https://github.com/actions/checkout/compare/v7...v7.0.1</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <h2>v7.0.1</h2> <ul> <li>Skip running unsafe pr check if input is default by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li> <li>Trim only ascii whitespace for branch by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li> <li>Escape values passed to --unset by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li> <li>Various dependency updates</li> </ul> <h2>v7.0.0</h2> <ul> <li>Block checking out fork PR for pull_request_target and workflow_run by <a href="https://github.com/aiqiaoy"><code>@aiqiaoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li> <li>Various dependency updates</li> </ul> <h2>v6.0.3</h2> <ul> <li>Fix checkout init for SHA-256 repositories by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li> <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a href="https://github.com/yaananth"><code>@yaananth</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li> </ul> <h2>v6.0.2</h2> <ul> <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li> </ul> <h2>v6.0.1</h2> <ul> <li>Add worktree support for persist-credentials includeIf by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li> </ul> <h2>v6.0.0</h2> <ul> <li>Persist creds to a separate file by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li> <li>Update README to include Node.js 24 support details and requirements by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li> </ul> <h2>v5.0.1</h2> <ul> <li>Port v6 cleanup to v5 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li> </ul> <h2>v5.0.0</h2> <ul> <li>Update actions checkout to use node 24 by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li> </ul> <h2>v4.3.1</h2> <ul> <li>Port v6 cleanup to v4 by <a href="https://github.com/ericsciple"><code>@ericsciple</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li> </ul> <h2>v4.3.0</h2> <ul> <li>docs: update README.md by <a href="https://github.com/motss"><code>@motss</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li> <li>Add internal repos for checking out multiple repositories by <a href="https://github.com/mouismail"><code>@mouismail</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li> <li>Documentation update - add recommended permissions to Readme by <a href="https://github.com/benwells"><code>@benwells</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li> <li>Adjust positioning of user email note and permissions heading by <a href="https://github.com/joshmgross"><code>@joshmgross</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li> <li>Update README.md by <a href="https://github.com/nebuk89"><code>@nebuk89</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li> <li>Update CODEOWNERS for actions by <a href="https://github.com/TingluoHuang"><code>@TingluoHuang</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li> <li>Update package dependencies by <a href="https://github.com/salmanmkc"><code>@salmanmkc</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li> </ul> <h2>v4.2.2</h2> <ul> <li><code>url-helper.ts</code> now leverages well-known environment variables by <a href="https://github.com/jww3"><code>@jww3</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li> <li>Expand unit test coverage for <code>isGhes</code> by <a href="https://github.com/jww3"><code>@jww3</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li> </ul> <h2>v4.2.1</h2> <ul> <li>Check out other refs/* by commit if provided, fall back to ref by <a href="https://github.com/orhantoy"><code>@orhantoy</code></a> in <a href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1"><code>3d3c42e</code></a> prep v7.0.1 release (<a href="https://redirect.github.com/actions/checkout/issues/2531">#2531</a>)</li> <li><a href="https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07"><code>2880268</code></a> escape values passed to --unset (<a href="https://redirect.github.com/actions/checkout/issues/2530">#2530</a>)</li> <li><a href="https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1"><code>12cd223</code></a> trim only ascii whitespace for branch (<a href="https://redirect.github.com/actions/checkout/issues/2521">#2521</a>)</li> <li><a href="https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541"><code>62661c4</code></a> skip running unsafe pr check if input is default (<a href="https://redirect.github.com/actions/checkout/issues/2518">#2518</a>)</li> <li><a href="https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f"><code>e8d4307</code></a> Bump the minor-actions-dependencies group with 2 updates (<a href="https://redirect.github.com/actions/checkout/issues/2499">#2499</a>)</li> <li><a href="https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87"><code>631c942</code></a> eslint 9 (<a href="https://redirect.github.com/actions/checkout/issues/2474">#2474</a>)</li> <li><a href="https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e"><code>4f1f4ae</code></a> Bump actions/upload-artifact from 4 to 7 (<a href="https://redirect.github.com/actions/checkout/issues/2476">#2476</a>)</li> <li><a href="https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92"><code>ba09753</code></a> Bump actions/checkout from 6 to 7 (<a href="https://redirect.github.com/actions/checkout/issues/2488">#2488</a>)</li> <li><a href="https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22"><code>b9e0990</code></a> Bump docker/login-action from 3.3.0 to 4.2.0 (<a href="https://redirect.github.com/actions/checkout/issues/2479">#2479</a>)</li> <li><a href="https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2"><code>e8cb398</code></a> Bump docker/build-push-action from 6.5.0 to 7.2.0 (<a href="https://redirect.github.com/actions/checkout/issues/2478">#2478</a>)</li> <li>Additional commits viewable in <a href="https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1">compare view</a></li> </ul> </details> <br /> Updates `pypa/gh-action-pypi-publish` from 1.14.0 to 1.14.2 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pypa/gh-action-pypi-publish/releases">pypa/gh-action-pypi-publish's releases</a>.</em></p> <blockquote> <h2>v1.14.2</h2> <!-- raw HTML omitted --> <h2>🛠️ Urgh… Another release!? Again? Explain yourself!</h2> <p>Looking at the diff, you'll only witness updates across the dependency tree. That's it! It's not a security fix or anything like that even, no. But you'll want this update.</p> <blockquote> <p>[!tip] So what <em>most</em> people will find useful is <a href="https://github.com/takluyver"><code>@takluyver</code></a><a href="https://github.com/sponsors/takluyver">💰</a>'s update of Twine to v7 that we use internally (<a href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416">#416</a>). This version will let them upload their sdists and wheels containing core packaging metadata v2.5 to (Test)PyPI.</p> </blockquote> <h2>🧐 Tell me why..</h2> <!-- raw HTML omitted --> <!-- raw HTML omitted --> <p>TL;DR non-pure-python projects with C-extensions tend to have dozens (sometimes hundreds) wheels to upload to PyPI per release. They are often quite big and take time to transfer over the network. People started noticing problems and coming up with DIY sharding workarounds like <a href="https://redirect.github.com/aio-libs/aiohttp/pull/13226">aio-libs/aiohttp#13226</a> around July 23. On this date, projects with a good amount of bytes to publish would start getting timeouts 5 minutes after the PyPI publishing job begun. The same job that worked just fine before.</p> <p>I had to start pinging upstream library and ecosystem people, on GitHub and privately, to start making sense of what was happening. Eventually, we collectively concluded that GitHub must've shortened the lifetime of their OIDC identity — it seems to have used to be 10 minutes long (at some point in the past) and is now 5 minutes, apparently. It's not documented clearly, and we have not been able to get any clarity by attempting to contact GitHub through private channels, using personal connections.</p> <p>Over the course of investigation, <a href="https://github.com/facutuesca"><code>@facutuesca</code></a><a href="https://github.com/sponsors/facutuesca">💰</a> found and fixed a related underlying cache invalidation bug in <a href="https://redirect.github.com/sigstore/sigstore-python/pull/1838">sigstore/sigstore-python#1838</a>, which he then coordinated propagation through the dependency chain updates in sigstore-python, pypi-attestations, gh-action-pypi-publish and gh-action-sigstore-python.</p> <p>Mike's also discovered that Sigstore's Rekor slowdown seems to have become the main contributing cause of the last week's incident. He's collected some data to support this claim: <a href="https://publishing-five-minute-timeout.tiiny.site">https://publishing-five-minute-timeout.tiiny.site</a>.</p> <!-- raw HTML omitted --> <!-- raw HTML omitted --> <h2>🫶 New Contributors</h2> <ul> <li><a href="https://github.com/davidbrochart"><code>@davidbrochart</code></a> made their first contribution in <a href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415">#415</a></li> <li><a href="https://github.com/takluyver"><code>@takluyver</code></a> made their first contribution in <a href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416">#416</a></li> </ul> <p><strong>🪞 Full Diff</strong>: <a href="https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2">https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2</a></p> <p><strong>🧔♂️ Release Manager:</strong> <a href="https://github.com/sponsors/webknjaz"><code>@webknjaz</code></a> <a href="https://stand-with-ukraine.pp.ua">🇺🇦</a></p> <p><strong>🙏 Special Thanks</strong> to <a href="https://github.com/davidbrochart"><code>@davidbrochart</code></a><a href="https://github.com/sponsors/davidbrochart">💰</a> and <a href="https://github.com/Dreamsorcerer"><code>@Dreamsorcerer</code></a><a href="https://github.com/sponsors/Dreamsorcerer">💰</a> for turning my attention (in <a href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415">#415</a> and in private) to the newly surfaced corner case in GitHub's behavior that only affected a narrow category of projects while many others remained blissfully unaware. <a href="https://github.com/bdraco"><code>@bdraco</code></a><a href="https://github.com/sponsors/bdraco">💰</a> came up with a DIY sharding workaround for aiohttp that served as a demo for other projects. <a href="https://github.com/miketheman"><code>@miketheman</code></a><a href="https://github.com/sponsors/miketheman">💰</a> confirmed the Warehouse-side details. Also, <a href="https://github.com/jku"><code>@jku</code></a><a href="https://github.com/sponsors/jku">💰</a> and <a href="https://github.com/woodruffw"><code>@woodruffw</code></a><a href="https://github.com/sponsors/woodruffw">💰</a> helped work through, review and release the Sigstore ecosystem upstream libs.</p> <p><strong>💬 Discuss</strong> <a href="https://bsky.app/profile/did:plc:ve6s3mxkefjaxty3m4fdqumn/post/3mrsqy2xba22j">on Bluesky 🦋</a>, <a href="https://mastodon.social/@webknjaz/117005132816750073">on Mastodon 🐘</a> and [on GitHub][release discussion].</p> <p>[![GH Sponsors badge]][GH Sponsors URL]</p> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pypa/gh-action-pypi-publish/commit/dc37677b2e1c63e2034f94d8a5b11f265b73ba33"><code>dc37677</code></a> Merge pull request <a href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/417">#417</a> from trail-of-forks/ft/bump-deps</li> <li><a href="https://github.com/pypa/gh-action-pypi-publish/commit/8b2f23418f024937cf97f77534a597947105e772"><code>8b2f234</code></a> Bump <code>pypi-attestations</code> and <code>sigstore</code></li> <li><a href="https://github.com/pypa/gh-action-pypi-publish/commit/78b72dbfed6e025eb89577c059edc936f8a2df14"><code>78b72db</code></a> Merge pull request <a href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416">#416</a> from takluyver/twine-v7</li> <li><a href="https://github.com/pypa/gh-action-pypi-publish/commit/92f4d2a159875dd135a7e56b7b3262f502b23a13"><code>92f4d2a</code></a> Update twine to v7</li> <li><a href="https://github.com/pypa/gh-action-pypi-publish/commit/ba38be9e461d3875417946c167d0b5f3d385a247"><code>ba38be9</code></a> Merge pull request <a href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/408">#408</a> from adisivaprasad/bump-setup-python-v6</li> <li><a href="https://github.com/pypa/gh-action-pypi-publish/commit/a6c5088d60d08ef54b70075735d25df696e5ccaa"><code>a6c5088</code></a> Bump actions/setup-python from v5.6.0 to v6.2.0</li> <li>See full diff in <a href="https://github.com/pypa/gh-action-pypi-publish/compare/cef221092ed1bacb1cc03d23a2d87d1d172e277b...dc37677b2e1c63e2034f94d8a5b11f265b73ba33">compare view</a></li> </ul> </details> <br /> Updates `aws-actions/configure-aws-credentials` from 6.2.1 to 6.2.3 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/aws-actions/configure-aws-credentials/releases">aws-actions/configure-aws-credentials's releases</a>.</em></p> <blockquote> <h2>v6.2.3</h2> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.2...v6.2.3">6.2.3</a> (2026-07-22)</h2> <h3>Bug Fixes</h3> <ul> <li>attach git credentials before Tag Major Version push (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1877">#1877</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/9ae780b171afa8c5a3a6a2d154a765b709492482">9ae780b</a>)</li> <li>PackedPolicyTooLarge detection in STS tags (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1899">#1899</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb">fa8d6a5</a>)</li> </ul> <h2>v6.2.2</h2> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2">6.2.2</a> (2026-07-07)</h2> <h3>Miscellaneous Chores</h3> <ul> <li>release 6.2.2 (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/d01d678e65d6d2bd9d5ca7a95d6f07b00e25f2c2">d01d678</a>)</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md">aws-actions/configure-aws-credentials's changelog</a>.</em></p> <blockquote> <h1>Changelog</h1> <p>All notable changes to this project will be documented in this file. See <a href="https://github.com/conventional-changelog/standard-version">standard-version</a> for commit guidelines.</p> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.2...v6.2.3">6.2.3</a> (2026-07-22)</h2> <h3>Bug Fixes</h3> <ul> <li>attach git credentials before Tag Major Version push (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1877">#1877</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/9ae780b171afa8c5a3a6a2d154a765b709492482">9ae780b</a>)</li> <li>PackedPolicyTooLarge detection in STS tags (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1899">#1899</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb">fa8d6a5</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.1...v6.2.2">6.2.2</a> (2026-07-07)</h2> <h3>Miscellaneous Chores</h3> <ul> <li>release 6.2.2 (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/d01d678e65d6d2bd9d5ca7a95d6f07b00e25f2c2">d01d678</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.2.0...v6.2.1">6.2.1</a> (2026-06-26)</h2> <h3>Bug Fixes</h3> <ul> <li>enforce allowed-account-ids on all auth paths (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1847">#1847</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/4d281fbc56a82e63c3fc14f2cc22361f34c97493">4d281fb</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.3...v6.2.0">6.2.0</a> (2026-06-01)</h2> <h3>Features</h3> <ul> <li>add additional session tags by default (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1775">#1775</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/e0ba7685077379a14a82d01fefd511490344ebfc">e0ba768</a>)</li> <li>add more retry logic and better logging (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1764">#1764</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/540d0c13aedb8d55501d220bd2f0b3cdedfe84e8">540d0c1</a>)</li> <li>add regex validation to role-session-name (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1765">#1765</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/e35449909c6ede5083a48ba4b8bbfaaa1cf09ba1">e354499</a>)</li> <li>Allow custom session tags to be passed when assuming a role (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1759">#1759</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/61f50f630f383628add73c1eab3f1935ba07da2b">61f50f6</a>)</li> <li>expose run id in STS client user-agent (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1774">#1774</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/29d1be30273e7ef371d59fccf6ec54572c64ec89">29d1be3</a>)</li> <li>support custom STS endpoints (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1762">#1762</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/8d52d05d7a4521fa52b39de50cb6114b12e5c332">8d52d05</a>)</li> </ul> <h3>Bug Fixes</h3> <ul> <li>skip credential check on output-env-credentials: false (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1778">#1778</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/58e7c47adf77846879008deadfeeef8a6969fe6c">58e7c47</a>)</li> <li>assumeRole failing from session tag size too large (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1808">#1808</a>) (<a href="https://github.com/aws-actions/configure-aws-credentials/commit/d6f5dc331b44474b19a52caaf85fa4d637b13c8e">d6f5dc3</a>)</li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.2...v6.1.3">6.1.3</a> (2026-05-28)</h2> <h3>Bug Fixes</h3> <ul> <li>fix: allow kubelet token symlink in <a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1805">#1805</a></li> </ul> <h2><a href="https://github.com/aws-actions/configure-aws-credentials/compare/v6.1.1...v6.1.2">6.1.2</a> (2026-05-26)</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/e6de054238d6b7531b4efff3b6587d9aade6a06c"><code>e6de054</code></a> chore(main): release 6.2.3 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1878">#1878</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/ab3b2ba025afb33b6856abfc1626992c70909302"><code>ab3b2ba</code></a> chore: Update dist</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/fa8d6a57bbf44b34439fb080bbdadc7c92c285eb"><code>fa8d6a5</code></a> fix: PackedPolicyTooLarge detection in STS tags (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1899">#1899</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/42e118a65655a9bcd2929e1ab7c4588fdd3255d3"><code>42e118a</code></a> chore(deps-dev): bump markdownlint-cli from 0.49.0 to 0.49.1 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1896">#1896</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/d86ddfcecc93d50cd1d1ca675d859403357c3d89"><code>d86ddfc</code></a> chore: Update dist</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/874aaac21e617e1544df3c6a9f043c9bc96adf70"><code>874aaac</code></a> chore(deps): bump <code>@aws-sdk/client-sts</code> from 3.1086.0 to 3.1091.0 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1892">#1892</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/d4341b65accaa2ddbb952380d8ef12f95043d338"><code>d4341b6</code></a> chore: Update dist</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/fe51823c9714409fc32ade60b0bb4e79890beff1"><code>fe51823</code></a> chore(deps-dev): bump <code>@aws-sdk/credential-provider-env</code> (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1894">#1894</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/a8be382115e1ad5c77c560af842deddb56cd375c"><code>a8be382</code></a> chore(deps-dev): bump <code>@biomejs/biome</code> from 2.5.3 to 2.5.4 (<a href="https://redirect.github.com/aws-actions/configure-aws-credentials/issues/1893">#1893</a>)</li> <li><a href="https://github.com/aws-actions/configure-aws-credentials/commit/e000376c2c1f88ccef5f22a6bda02c24932d8ea5"><code>e000376</code></a> chore: Update dist</li> <li>Additional commits viewable in <a href="https://github.com/aws-actions/configure-aws-credentials/compare/254c19bd240aabef8777f48595e9d2d7b972184b...e6de054238d6b7531b4efff3b6587d9aade6a06c">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
915 lines
38 KiB
YAML
915 lines
38 KiB
YAML
# Builds and publishes LangChain packages to PyPI.
|
|
#
|
|
# Manually triggered, though can be used as a reusable workflow (workflow_call).
|
|
#
|
|
# Handles version bumping, building, and publishing to PyPI with authentication.
|
|
|
|
name: "🚀 Package Release"
|
|
# Run title resolves dropdown values to the published package name (e.g.
|
|
# `core` -> `langchain-core`, `openai` -> `langchain-openai`). Falls back to
|
|
# the raw input for override and `workflow_call` cases, which already pass
|
|
# a full path. Three dropdown values don't follow `langchain-{name}`:
|
|
# `langchain` -> `langchain-classic`, `langchain_v1` -> `langchain`,
|
|
# `standard-tests` -> `langchain-tests`.
|
|
run-name: >-
|
|
Release ${{ inputs.working-directory-override ||
|
|
(startsWith(inputs.working-directory, 'libs/') && inputs.working-directory) ||
|
|
(inputs.working-directory == 'langchain' && 'langchain-classic') ||
|
|
(inputs.working-directory == 'langchain_v1' && 'langchain') ||
|
|
(inputs.working-directory == 'standard-tests' && 'langchain-tests') ||
|
|
format('langchain-{0}', inputs.working-directory) }} ${{
|
|
inputs.release-version }}
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
working-directory:
|
|
required: true
|
|
type: string
|
|
description: "From which folder this pipeline executes"
|
|
release-version:
|
|
required: false
|
|
type: string
|
|
default: ""
|
|
description: "Expected package version. If provided, must match pyproject.toml."
|
|
allow-prereleases:
|
|
required: false
|
|
type: boolean
|
|
default: false
|
|
description: "Pass `--prerelease=allow` to wheel-install steps so
|
|
transitive prerelease deps (e.g. langgraph-checkpoint>=4.1.0a3 pulled
|
|
in by an alpha langgraph) resolve. Use only when the release itself
|
|
is a prerelease and at least one dep is also a prerelease."
|
|
# `workflow_call` callers must pass an exact lowercase value: `none` or a
|
|
# partner name from the `test-prior-published-packages-against-new-core`
|
|
# matrix (or `all`). Unrecognized values fail safe (the check still runs).
|
|
# Keep this list in sync with that matrix and the `workflow_dispatch`
|
|
# `options` below.
|
|
skip-prior-published-package-checks:
|
|
required: false
|
|
type: string
|
|
default: "none"
|
|
description: "Prior published partner check to skip for core releases:
|
|
none, anthropic, openai, or all."
|
|
workflow_dispatch:
|
|
inputs:
|
|
working-directory:
|
|
required: true
|
|
type: choice
|
|
description: "From which folder this pipeline executes"
|
|
default: "langchain_v1"
|
|
# Short names only — `EFFECTIVE_WORKING_DIR` below re-adds the `libs/`
|
|
# or `libs/partners/` prefix. When adding a new option, also update the
|
|
# non-partner allowlist in `EFFECTIVE_WORKING_DIR` if it isn't a partner
|
|
# package (partners are the default branch).
|
|
options:
|
|
- core
|
|
- langchain
|
|
- langchain_v1
|
|
- text-splitters
|
|
- standard-tests
|
|
- model-profiles
|
|
- anthropic
|
|
- chroma
|
|
- deepseek
|
|
- exa
|
|
- fireworks
|
|
- groq
|
|
- huggingface
|
|
- mistralai
|
|
- nomic
|
|
- ollama
|
|
- openai
|
|
- openrouter
|
|
- perplexity
|
|
- qdrant
|
|
- xai
|
|
working-directory-override:
|
|
required: false
|
|
type: string
|
|
description: "Manual override — takes precedence over dropdown (e.g.
|
|
libs/partners/partner-xyz)"
|
|
release-version:
|
|
required: true
|
|
type: string
|
|
default: "0.1.0"
|
|
description: "New version of package being released"
|
|
dangerous-nonmaster-release:
|
|
required: false
|
|
type: boolean
|
|
default: false
|
|
description: "Release from a non-master branch (danger!) - Only use for hotfixes"
|
|
allow-prereleases:
|
|
required: false
|
|
type: boolean
|
|
default: false
|
|
description: "Pass `--prerelease=allow` to wheel-install steps so
|
|
transitive prerelease deps (e.g. langgraph-checkpoint>=4.1.0a3 pulled
|
|
in by an alpha langgraph) resolve. Use only when the release itself
|
|
is a prerelease and at least one dep is also a prerelease."
|
|
skip-prior-published-package-checks:
|
|
required: false
|
|
type: choice
|
|
default: none
|
|
description: "Prior published partner check to skip for core releases"
|
|
options:
|
|
- none
|
|
- anthropic
|
|
- openai
|
|
- all
|
|
|
|
env:
|
|
PYTHON_VERSION: "3.11"
|
|
UV_FROZEN: "true"
|
|
UV_NO_SYNC: "true"
|
|
# Resolves to a full path. Accepts either:
|
|
# - `working-directory-override` as a full path (e.g. `libs/partners/partner-xyz`)
|
|
# - `working-directory` as a full path (from `workflow_call` callers)
|
|
# - `working-directory` as a short dropdown name (from `workflow_dispatch`)
|
|
EFFECTIVE_WORKING_DIR: >-
|
|
${{
|
|
inputs.working-directory-override
|
|
|| (startsWith(inputs.working-directory, 'libs/') && inputs.working-directory)
|
|
|| (contains(fromJSON('["core","langchain","langchain_v1","text-splitters","standard-tests","model-profiles"]'), inputs.working-directory) && format('libs/{0}', inputs.working-directory))
|
|
|| format('libs/partners/{0}', inputs.working-directory)
|
|
}}
|
|
|
|
permissions:
|
|
contents: read # Job-level overrides grant write only where needed (mark-release)
|
|
|
|
jobs:
|
|
# Build the distribution package and extract version info
|
|
# Runs in isolated environment with minimal permissions for security
|
|
build:
|
|
name: 📦 Build distribution
|
|
if: github.repository_owner == 'langchain-ai' && (github.ref == 'refs/heads/master' || inputs.dangerous-nonmaster-release)
|
|
environment: Release
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
|
|
outputs:
|
|
pkg-name: ${{ steps.check-version.outputs.pkg-name }}
|
|
version: ${{ steps.check-version.outputs.version }}
|
|
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
|
|
|
|
- name: Set up Python + uv
|
|
uses: "./.github/actions/uv_setup"
|
|
with:
|
|
python-version: ${{ env.PYTHON_VERSION }}
|
|
enable-cache: "false"
|
|
|
|
- name: Summarize release bypasses
|
|
if: >-
|
|
inputs.dangerous-nonmaster-release || inputs.allow-prereleases ||
|
|
inputs.skip-prior-published-package-checks != 'none'
|
|
env:
|
|
ALLOW_PRERELEASES: ${{ inputs.allow-prereleases }}
|
|
DANGEROUS_NONMASTER_RELEASE: ${{ inputs.dangerous-nonmaster-release }}
|
|
SKIP_PRIOR_PUBLISHED_PACKAGE_CHECKS: ${{ inputs.skip-prior-published-package-checks }}
|
|
run: |
|
|
echo "::warning::Release bypass input(s) enabled. See job summary."
|
|
{
|
|
echo "## ⚠️ Release bypasses enabled"
|
|
echo
|
|
echo "One or more release safety bypasses were selected for this run:"
|
|
echo
|
|
if [ "$DANGEROUS_NONMASTER_RELEASE" = "true" ]; then
|
|
echo "- \`dangerous-nonmaster-release\`: release jobs may run from a non-\`master\` ref."
|
|
fi
|
|
if [ "$ALLOW_PRERELEASES" = "true" ]; then
|
|
echo "- \`allow-prereleases\`: install checks use \`--prerelease=allow\`."
|
|
fi
|
|
if [ -n "$SKIP_PRIOR_PUBLISHED_PACKAGE_CHECKS" ] && [ "$SKIP_PRIOR_PUBLISHED_PACKAGE_CHECKS" != "none" ]; then
|
|
echo "- \`skip-prior-published-package-checks\`: \`$SKIP_PRIOR_PUBLISHED_PACKAGE_CHECKS\`."
|
|
fi
|
|
} >> "$GITHUB_STEP_SUMMARY"
|
|
|
|
- name: Check version
|
|
id: check-version
|
|
shell: python
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
env:
|
|
RELEASE_VERSION_INPUT: ${{ inputs.release-version }}
|
|
run: |
|
|
import os
|
|
import re
|
|
import sys
|
|
import tomllib
|
|
import urllib.error
|
|
import urllib.request
|
|
|
|
with open("pyproject.toml", "rb") as f:
|
|
data = tomllib.load(f)
|
|
|
|
pkg_name = data["project"]["name"]
|
|
version = data["project"]["version"]
|
|
requested_version = os.environ.get("RELEASE_VERSION_INPUT", "").strip()
|
|
|
|
|
|
def normalize(v):
|
|
# Lightweight PEP 440 comparison key: lowercase and drop the `-`,
|
|
# `_`, or `.` separators that precede a pre/post/dev segment so that
|
|
# e.g. `0.1.0-rc1` and `0.1.0rc1` compare equal. Full canonicalization
|
|
# lives in `packaging`, which isn't installed in this bare release step.
|
|
return re.sub(r"[-_.]+(?=[a-z])", "", v.lower())
|
|
|
|
|
|
if requested_version and normalize(requested_version) != normalize(version):
|
|
print(
|
|
f"::error::Requested release version {requested_version!r} does "
|
|
f"not match {pkg_name} pyproject.toml version {version!r}."
|
|
)
|
|
sys.exit(1)
|
|
|
|
# Query the per-version endpoint so PyPI applies PEP 440 normalization
|
|
# (e.g. `0.1.0-rc1` and `0.1.0rc1` resolve to the same release): HTTP 200
|
|
# means the version is already published, 404 means it's available
|
|
# (including the first-ever release of a new package). Only the status
|
|
# code is used, so a malicious or malformed response body can't mislead us.
|
|
url = f"https://pypi.org/pypi/{pkg_name}/{version}/json"
|
|
try:
|
|
with urllib.request.urlopen(url, timeout=10):
|
|
already_published = True
|
|
except urllib.error.HTTPError as err:
|
|
if err.code == 404:
|
|
already_published = False
|
|
else:
|
|
# Fail closed: an unexpected status means we can't verify.
|
|
print(
|
|
f"::error::PyPI returned HTTP {err.code} checking whether "
|
|
f"{pkg_name}=={version} exists; cannot verify, aborting."
|
|
)
|
|
sys.exit(1)
|
|
except urllib.error.URLError as err:
|
|
# Fail closed: if PyPI is unreachable we must not assume the version
|
|
# is free, or we risk re-publishing an existing release.
|
|
print(
|
|
f"::error::Could not reach PyPI to verify {pkg_name}=={version} "
|
|
f"({err.reason}); cannot verify, aborting."
|
|
)
|
|
sys.exit(1)
|
|
|
|
if already_published:
|
|
print(f"::error::{pkg_name}=={version} already exists on PyPI.")
|
|
sys.exit(1)
|
|
|
|
|
|
with open(os.environ["GITHUB_OUTPUT"], "a") as f:
|
|
f.write(f"pkg-name={pkg_name}\n")
|
|
f.write(f"version={version}\n")
|
|
|
|
# We want to keep this build stage *separate* from the release stage,
|
|
# so that there's no sharing of permissions between them.
|
|
# (Release stage has trusted publishing and GitHub repo contents write access,
|
|
# which the build stage must not have access to.)
|
|
#
|
|
# Otherwise, a malicious `build` step (e.g. via a compromised dependency)
|
|
# could get access to our GitHub or PyPI credentials.
|
|
#
|
|
# Per the trusted publishing GitHub Action:
|
|
# > It is strongly advised to separate jobs for building [...]
|
|
# > from the publish job.
|
|
# https://github.com/pypa/gh-action-pypi-publish#non-goals
|
|
- name: Build project for distribution
|
|
run: uv build
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
|
|
- name: Upload build
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
with:
|
|
name: dist
|
|
path: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/
|
|
release-notes:
|
|
name: 📝 Generate release notes
|
|
# release-notes must run before publishing because its check-tags step
|
|
# validates version/tag state — do not remove this dependency.
|
|
needs:
|
|
- build
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
outputs:
|
|
release-body: ${{ steps.generate-release-body.outputs.release-body }}
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
|
|
with:
|
|
repository: langchain-ai/langchain
|
|
path: langchain
|
|
sparse-checkout: | # this only grabs files for relevant dir
|
|
${{ env.EFFECTIVE_WORKING_DIR }}
|
|
ref: ${{ github.ref }} # this scopes to just ref'd branch
|
|
fetch-depth: 0 # this fetches entire commit history
|
|
- name: Check tags
|
|
id: check-tags
|
|
shell: bash
|
|
working-directory: langchain/${{ env.EFFECTIVE_WORKING_DIR }}
|
|
env:
|
|
PKG_NAME: ${{ needs.build.outputs.pkg-name }}
|
|
VERSION: ${{ needs.build.outputs.version }}
|
|
run: |
|
|
# Handle regular versions and pre-release versions differently
|
|
if [[ "$VERSION" == *"-"* ]]; then
|
|
# This is a pre-release version (contains a hyphen)
|
|
# Extract the base version without the pre-release suffix
|
|
BASE_VERSION=${VERSION%%-*}
|
|
# Look for the latest release of the same base version
|
|
REGEX="^$PKG_NAME==$BASE_VERSION\$"
|
|
PREV_TAG=$(git tag --sort=-creatordate | (grep -P "$REGEX" || true) | head -1)
|
|
|
|
# If no exact base version match, look for the latest release of any kind
|
|
if [ -z "$PREV_TAG" ]; then
|
|
REGEX="^$PKG_NAME==\\d+\\.\\d+\\.\\d+\$"
|
|
PREV_TAG=$(git tag --sort=-creatordate | (grep -P "$REGEX" || true) | head -1)
|
|
fi
|
|
else
|
|
# Regular version handling
|
|
PREV_TAG="$PKG_NAME==${VERSION%.*}.$(( ${VERSION##*.} - 1 ))"; [[ "${VERSION##*.}" -eq 0 ]] && PREV_TAG=""
|
|
|
|
# backup case if releasing e.g. 0.3.0, looks up last release
|
|
# note if last release (chronologically) was e.g. 0.1.47 it will get
|
|
# that instead of the last 0.2 release
|
|
if [ -z "$PREV_TAG" ]; then
|
|
REGEX="^$PKG_NAME==\\d+\\.\\d+\\.\\d+\$"
|
|
echo $REGEX
|
|
PREV_TAG=$(git tag --sort=-creatordate | (grep -P $REGEX || true) | head -1)
|
|
fi
|
|
fi
|
|
|
|
# if PREV_TAG is empty or came out to 0.0.0, let it be empty
|
|
if [ -z "$PREV_TAG" ] || [ "$PREV_TAG" = "$PKG_NAME==0.0.0" ]; then
|
|
echo "No previous tag found - first release"
|
|
else
|
|
# confirm prev-tag actually exists in git repo with git tag
|
|
GIT_TAG_RESULT=$(git tag -l "$PREV_TAG")
|
|
if [ -z "$GIT_TAG_RESULT" ]; then
|
|
echo "Previous tag $PREV_TAG not found in git repo"
|
|
exit 1
|
|
fi
|
|
fi
|
|
|
|
|
|
TAG="${PKG_NAME}==${VERSION}"
|
|
if [ "$TAG" == "$PREV_TAG" ]; then
|
|
echo "No new version to release"
|
|
exit 1
|
|
fi
|
|
echo tag="$TAG" >> $GITHUB_OUTPUT
|
|
echo prev-tag="$PREV_TAG" >> $GITHUB_OUTPUT
|
|
- name: Generate release body
|
|
id: generate-release-body
|
|
working-directory: langchain
|
|
env:
|
|
WORKING_DIR: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
PKG_NAME: ${{ needs.build.outputs.pkg-name }}
|
|
TAG: ${{ steps.check-tags.outputs.tag }}
|
|
PREV_TAG: ${{ steps.check-tags.outputs.prev-tag }}
|
|
run: |
|
|
PREAMBLE="Changes since $PREV_TAG"
|
|
# if PREV_TAG is empty or 0.0.0, then we are releasing the first version
|
|
if [ -z "$PREV_TAG" ] || [ "$PREV_TAG" = "$PKG_NAME==0.0.0" ]; then
|
|
PREAMBLE="Initial release"
|
|
PREV_TAG=$(git rev-list --max-parents=0 HEAD)
|
|
fi
|
|
{
|
|
echo 'release-body<<EOF'
|
|
echo $PREAMBLE
|
|
echo
|
|
git log --format="%s" "$PREV_TAG"..HEAD -- $WORKING_DIR
|
|
echo EOF
|
|
} >> "$GITHUB_OUTPUT"
|
|
|
|
pre-release-checks:
|
|
name: ✅ Pre-release checks
|
|
needs:
|
|
- build
|
|
- release-notes
|
|
environment: Release
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
timeout-minutes: 20
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
|
|
|
|
# We explicitly *don't* set up caching here. This ensures our tests are
|
|
# maximally sensitive to catching breakage.
|
|
#
|
|
# For example, here's a way that caching can cause a falsely-passing test:
|
|
# - Make the langchain package manifest no longer list a dependency package
|
|
# as a requirement. This means it won't be installed by `pip install`,
|
|
# and attempting to use it would cause a crash.
|
|
# - That dependency used to be required, so it may have been cached.
|
|
# When restoring the venv packages from cache, that dependency gets included.
|
|
# - Tests pass, because the dependency is present even though it wasn't specified.
|
|
# - The package is published, and it breaks on the missing dependency when
|
|
# used in the real world.
|
|
|
|
- name: Set up Python + uv
|
|
uses: "./.github/actions/uv_setup"
|
|
id: setup-python
|
|
with:
|
|
python-version: ${{ env.PYTHON_VERSION }}
|
|
enable-cache: "false"
|
|
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
with:
|
|
name: dist
|
|
path: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/
|
|
|
|
- name: Import dist package
|
|
shell: bash
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
env:
|
|
PKG_NAME: ${{ needs.build.outputs.pkg-name }}
|
|
VERSION: ${{ needs.build.outputs.version }}
|
|
PRERELEASE_FLAG: ${{ inputs.allow-prereleases && '--prerelease=allow' || '' }}
|
|
# Install directly from the locally-built wheel (no index resolution needed).
|
|
# `PRERELEASE_FLAG` is empty by default; opt-in via the `allow-prereleases`
|
|
# workflow input lets transitive prerelease deps resolve during alpha
|
|
# release cycles. Stable-release safety is still enforced by the
|
|
# `Check for prerelease versions` step below.
|
|
run: |
|
|
uv venv
|
|
VIRTUAL_ENV=.venv uv pip install $PRERELEASE_FLAG dist/*.whl
|
|
|
|
# Replace all dashes in the package name with underscores,
|
|
# since that's how Python imports packages with dashes in the name.
|
|
# also remove _official suffix
|
|
IMPORT_NAME="$(echo "$PKG_NAME" | sed s/-/_/g | sed s/_official//g)"
|
|
|
|
uv run python -c "import $IMPORT_NAME; print(dir($IMPORT_NAME))"
|
|
|
|
- name: Import test dependencies
|
|
run: uv sync --group test
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
|
|
# Overwrite the local version of the package with the built version
|
|
- name: Import published package (again)
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
shell: bash
|
|
env:
|
|
PKG_NAME: ${{ needs.build.outputs.pkg-name }}
|
|
VERSION: ${{ needs.build.outputs.version }}
|
|
PRERELEASE_FLAG: ${{ inputs.allow-prereleases && '--prerelease=allow' || '' }}
|
|
run: |
|
|
VIRTUAL_ENV=.venv uv pip install $PRERELEASE_FLAG dist/*.whl
|
|
|
|
- name: Check for prerelease versions
|
|
# Block release if any dependencies allow prerelease versions
|
|
# (unless this is itself a prerelease version)
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
run: |
|
|
uv run python $GITHUB_WORKSPACE/.github/scripts/check_prerelease_dependencies.py pyproject.toml
|
|
|
|
- name: Run unit tests
|
|
run: make tests
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
|
|
- name: Get minimum versions
|
|
# Find the minimum published versions that satisfies the given constraints
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
id: min-version
|
|
run: |
|
|
VIRTUAL_ENV=.venv uv pip install packaging requests
|
|
python_version="$(uv run python --version | awk '{print $2}')"
|
|
min_versions="$(uv run python $GITHUB_WORKSPACE/.github/scripts/get_min_versions.py pyproject.toml release $python_version)"
|
|
echo "min-versions=$min_versions" >> "$GITHUB_OUTPUT"
|
|
echo "min-versions=$min_versions"
|
|
|
|
- name: Run unit tests with minimum dependency versions
|
|
if: ${{ steps.min-version.outputs.min-versions != '' }}
|
|
env:
|
|
MIN_VERSIONS: ${{ steps.min-version.outputs.min-versions }}
|
|
PRERELEASE_FLAG: ${{ inputs.allow-prereleases && '--prerelease=allow' || '' }}
|
|
run: |
|
|
VIRTUAL_ENV=.venv uv pip install $PRERELEASE_FLAG --force-reinstall --editable .
|
|
VIRTUAL_ENV=.venv uv pip install $PRERELEASE_FLAG --force-reinstall $MIN_VERSIONS
|
|
make tests PYTEST_EXTRA="-q -k 'not test_serdes'"
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
|
|
- name: Import integration test dependencies
|
|
run: uv sync --group test --group test_integration
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
|
|
- name: Run integration tests
|
|
# Uses the Makefile's `integration_tests` target for the specified package
|
|
if: ${{ startsWith(env.EFFECTIVE_WORKING_DIR, 'libs/partners/') }}
|
|
env:
|
|
AI21_API_KEY: ${{ secrets.AI21_API_KEY }}
|
|
GOOGLE_API_KEY: ${{ secrets.GOOGLE_API_KEY }}
|
|
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
|
|
MISTRAL_API_KEY: ${{ secrets.MISTRAL_API_KEY }}
|
|
TOGETHER_API_KEY: ${{ secrets.TOGETHER_API_KEY }}
|
|
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
|
|
AZURE_OPENAI_API_VERSION: ${{ secrets.AZURE_OPENAI_API_VERSION }}
|
|
AZURE_OPENAI_API_BASE: ${{ secrets.AZURE_OPENAI_API_BASE }}
|
|
AZURE_OPENAI_API_KEY: ${{ secrets.AZURE_OPENAI_API_KEY }}
|
|
AZURE_OPENAI_CHAT_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_CHAT_DEPLOYMENT_NAME }}
|
|
AZURE_OPENAI_LEGACY_CHAT_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_LEGACY_CHAT_DEPLOYMENT_NAME }}
|
|
AZURE_OPENAI_LLM_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_LLM_DEPLOYMENT_NAME }}
|
|
AZURE_OPENAI_EMBEDDINGS_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_EMBEDDINGS_DEPLOYMENT_NAME }}
|
|
NVIDIA_API_KEY: ${{ secrets.NVIDIA_API_KEY }}
|
|
GOOGLE_SEARCH_API_KEY: ${{ secrets.GOOGLE_SEARCH_API_KEY }}
|
|
GOOGLE_CSE_ID: ${{ secrets.GOOGLE_CSE_ID }}
|
|
GROQ_API_KEY: ${{ secrets.GROQ_API_KEY }}
|
|
HUGGINGFACEHUB_API_TOKEN: ${{ secrets.HUGGINGFACEHUB_API_TOKEN }}
|
|
EXA_API_KEY: ${{ secrets.EXA_API_KEY }}
|
|
NOMIC_API_KEY: ${{ secrets.NOMIC_API_KEY }}
|
|
WATSONX_APIKEY: ${{ secrets.WATSONX_APIKEY }}
|
|
WATSONX_PROJECT_ID: ${{ secrets.WATSONX_PROJECT_ID }}
|
|
ASTRA_DB_API_ENDPOINT: ${{ secrets.ASTRA_DB_API_ENDPOINT }}
|
|
ASTRA_DB_APPLICATION_TOKEN: ${{ secrets.ASTRA_DB_APPLICATION_TOKEN }}
|
|
ASTRA_DB_KEYSPACE: ${{ secrets.ASTRA_DB_KEYSPACE }}
|
|
ES_URL: ${{ secrets.ES_URL }}
|
|
ES_CLOUD_ID: ${{ secrets.ES_CLOUD_ID }}
|
|
ES_API_KEY: ${{ secrets.ES_API_KEY }}
|
|
MONGODB_ATLAS_URI: ${{ secrets.MONGODB_ATLAS_URI }}
|
|
UPSTAGE_API_KEY: ${{ secrets.UPSTAGE_API_KEY }}
|
|
FIREWORKS_API_KEY: ${{ secrets.FIREWORKS_API_KEY }}
|
|
XAI_API_KEY: ${{ secrets.XAI_API_KEY }}
|
|
DEEPSEEK_API_KEY: ${{ secrets.DEEPSEEK_API_KEY }}
|
|
PPLX_API_KEY: ${{ secrets.PPLX_API_KEY }}
|
|
OLLAMA_API_KEY: ${{ secrets.OLLAMA_API_KEY }}
|
|
OPENROUTER_API_KEY: ${{ secrets.OPENROUTER_API_KEY }}
|
|
LANGCHAIN_TESTS_USER_AGENT: ${{ secrets.LANGCHAIN_TESTS_USER_AGENT }}
|
|
run: make integration_tests
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
|
|
test-pypi-publish:
|
|
name: 🧪 Publish to TestPyPI
|
|
# release-notes must run before publishing because its check-tags step
|
|
# validates version/tag state — do not remove this dependency.
|
|
needs:
|
|
- build
|
|
- release-notes
|
|
- pre-release-checks
|
|
environment: Release
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
# This permission is used for trusted publishing:
|
|
# https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
|
|
#
|
|
# Trusted publishing has to also be configured on PyPI for each package:
|
|
# https://docs.pypi.org/trusted-publishers/adding-a-publisher/
|
|
id-token: write
|
|
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
|
|
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
with:
|
|
name: dist
|
|
path: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/
|
|
|
|
- name: Publish to test PyPI
|
|
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1
|
|
with:
|
|
packages-dir: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/
|
|
verbose: true
|
|
print-hash: true
|
|
repository-url: https://test.pypi.org/legacy/
|
|
# We overwrite any existing distributions with the same name and version.
|
|
# This is *only for CI use* and is *extremely dangerous* otherwise!
|
|
# https://github.com/pypa/gh-action-pypi-publish#tolerating-release-package-file-duplicates
|
|
skip-existing: true
|
|
# Temp workaround since attestations are on by default as of gh-action-pypi-publish v1.11.0
|
|
attestations: false
|
|
|
|
# Test select published packages against new core
|
|
# Done when code changes are made to langchain-core
|
|
test-prior-published-packages-against-new-core:
|
|
name: 🔄 Test prior partners against new core
|
|
# Installs the new core with old partners: Installs the new unreleased core
|
|
# alongside the previously published partner packages and runs unit and integration tests
|
|
needs:
|
|
- build
|
|
- release-notes
|
|
- test-pypi-publish
|
|
- pre-release-checks
|
|
environment: Release
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
strategy:
|
|
matrix:
|
|
# When adding a partner, also update the `skip-prior-published-package-checks`
|
|
# input (the `workflow_dispatch` `options` list and the `workflow_call`
|
|
# description) so the per-partner skip remains selectable.
|
|
partner: [ anthropic, openai ]
|
|
fail-fast: false # Continue testing other partners if one fails
|
|
env:
|
|
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
|
|
ANTHROPIC_FILES_API_IMAGE_ID: ${{ secrets.ANTHROPIC_FILES_API_IMAGE_ID }}
|
|
ANTHROPIC_FILES_API_PDF_ID: ${{ secrets.ANTHROPIC_FILES_API_PDF_ID }}
|
|
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
|
|
AZURE_OPENAI_API_VERSION: ${{ secrets.AZURE_OPENAI_API_VERSION }}
|
|
AZURE_OPENAI_API_BASE: ${{ secrets.AZURE_OPENAI_API_BASE }}
|
|
AZURE_OPENAI_API_KEY: ${{ secrets.AZURE_OPENAI_API_KEY }}
|
|
AZURE_OPENAI_CHAT_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_CHAT_DEPLOYMENT_NAME }}
|
|
AZURE_OPENAI_LEGACY_CHAT_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_LEGACY_CHAT_DEPLOYMENT_NAME }}
|
|
AZURE_OPENAI_LLM_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_LLM_DEPLOYMENT_NAME }}
|
|
AZURE_OPENAI_EMBEDDINGS_DEPLOYMENT_NAME: ${{ secrets.AZURE_OPENAI_EMBEDDINGS_DEPLOYMENT_NAME }}
|
|
LANGCHAIN_TESTS_USER_AGENT: ${{ secrets.LANGCHAIN_TESTS_USER_AGENT }}
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
|
|
|
|
# We implement this conditional as Github Actions does not have good support
|
|
# for conditionally needing steps. https://github.com/actions/runner/issues/491
|
|
# TODO: this seems to be resolved upstream, so we can probably remove this workaround
|
|
- name: Check if libs/core
|
|
run: |
|
|
if [ "${{ startsWith(env.EFFECTIVE_WORKING_DIR, 'libs/core') }}" != "true" ]; then
|
|
echo "Not in libs/core. Exiting successfully."
|
|
exit 0
|
|
fi
|
|
|
|
- name: Set up Python + uv
|
|
if: startsWith(env.EFFECTIVE_WORKING_DIR, 'libs/core')
|
|
uses: "./.github/actions/uv_setup"
|
|
with:
|
|
python-version: ${{ env.PYTHON_VERSION }}
|
|
enable-cache: "false"
|
|
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
if: startsWith(env.EFFECTIVE_WORKING_DIR, 'libs/core')
|
|
with:
|
|
name: dist
|
|
path: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/
|
|
|
|
- name: Skip prior published ${{ matrix.partner }} check
|
|
if: >-
|
|
startsWith(env.EFFECTIVE_WORKING_DIR, 'libs/core') &&
|
|
(inputs.skip-prior-published-package-checks == matrix.partner ||
|
|
inputs.skip-prior-published-package-checks == 'all')
|
|
run: |
|
|
echo "Skipping prior published ${{ matrix.partner }} check as requested."
|
|
|
|
- name: Test against ${{ matrix.partner }}
|
|
if: >-
|
|
startsWith(env.EFFECTIVE_WORKING_DIR, 'libs/core') &&
|
|
inputs.skip-prior-published-package-checks != matrix.partner &&
|
|
inputs.skip-prior-published-package-checks != 'all'
|
|
env:
|
|
PARTNER: ${{ matrix.partner }}
|
|
PRERELEASE_FLAG: ${{ inputs.allow-prereleases && '--prerelease=allow' || '' }}
|
|
run: |
|
|
PACKAGE_NAME="langchain-$PARTNER"
|
|
|
|
# Identify the latest non-yanked published package release, excluding pre-releases.
|
|
# Fail closed (matching the `Check version` step) so a PyPI outage or a
|
|
# missing release aborts with a clear message rather than an empty version.
|
|
LATEST_PACKAGE_VERSION="$(PACKAGE_NAME="$PACKAGE_NAME" python - <<'PY'
|
|
import json
|
|
import os
|
|
import re
|
|
import sys
|
|
import urllib.error
|
|
import urllib.request
|
|
|
|
package_name = os.environ["PACKAGE_NAME"]
|
|
url = f"https://pypi.org/pypi/{package_name}/json"
|
|
try:
|
|
with urllib.request.urlopen(url, timeout=10) as response:
|
|
data = json.load(response)
|
|
except urllib.error.HTTPError as err:
|
|
print(
|
|
f"::error::PyPI returned HTTP {err.code} listing {package_name} "
|
|
f"releases; cannot determine latest version, aborting.",
|
|
file=sys.stderr,
|
|
)
|
|
sys.exit(1)
|
|
except urllib.error.URLError as err:
|
|
print(
|
|
f"::error::Could not reach PyPI to list {package_name} releases "
|
|
f"({err.reason}); cannot determine latest version, aborting.",
|
|
file=sys.stderr,
|
|
)
|
|
sys.exit(1)
|
|
|
|
versions: list[tuple[int, int, int, str]] = []
|
|
for version, files in data["releases"].items():
|
|
if not re.fullmatch(r"\d+\.\d+\.\d+", version):
|
|
continue
|
|
if not files or all(file.get("yanked", False) for file in files):
|
|
continue
|
|
versions.append((*map(int, version.split(".")), version))
|
|
|
|
if not versions:
|
|
print(f"::error::No non-yanked final releases found for {package_name}", file=sys.stderr)
|
|
sys.exit(1)
|
|
|
|
print(max(versions)[3])
|
|
PY
|
|
)"
|
|
|
|
# Belt-and-suspenders: a bare assignment masks the heredoc's exit status
|
|
# in some shells, so guard explicitly rather than relying on `set -e`.
|
|
if [ -z "$LATEST_PACKAGE_VERSION" ]; then
|
|
echo "::error::Could not determine latest published $PACKAGE_NAME version; aborting."
|
|
exit 1
|
|
fi
|
|
|
|
LATEST_PACKAGE_TAG="$PACKAGE_NAME==$LATEST_PACKAGE_VERSION"
|
|
echo "Latest non-yanked package tag: $LATEST_PACKAGE_TAG"
|
|
|
|
# Ensure the PyPI release maps to a source tag before running tests.
|
|
git ls-remote --exit-code --tags origin "refs/tags/$LATEST_PACKAGE_TAG"
|
|
|
|
# Shallow-fetch just that single tag
|
|
git fetch --depth=1 origin tag "$LATEST_PACKAGE_TAG"
|
|
|
|
# Checkout the latest package files
|
|
rm -rf "$GITHUB_WORKSPACE/libs/partners/$PARTNER"/*
|
|
rm -rf $GITHUB_WORKSPACE/libs/standard-tests/*
|
|
cd $GITHUB_WORKSPACE/libs/
|
|
git checkout "$LATEST_PACKAGE_TAG" -- standard-tests/
|
|
git checkout "$LATEST_PACKAGE_TAG" -- "partners/$PARTNER/"
|
|
cd "partners/$PARTNER"
|
|
|
|
# Print as a sanity check
|
|
echo "Version number from pyproject.toml: "
|
|
cat pyproject.toml | grep "version = "
|
|
|
|
# Run tests
|
|
uv sync --group test --group test_integration
|
|
uv pip install $PRERELEASE_FLAG ../../core/dist/*.whl
|
|
make test
|
|
make integration_tests
|
|
|
|
# Test external packages that depend on langchain-core/langchain against the new release
|
|
# Only runs for core and langchain_v1 releases to catch breaking changes before publish
|
|
test-dependents:
|
|
name: "🐍 Test dependent: ${{ matrix.package.path }} (Python ${{
|
|
matrix.python-version }})"
|
|
needs:
|
|
- build
|
|
- release-notes
|
|
- test-pypi-publish
|
|
- pre-release-checks
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
# Only run for core or langchain_v1 releases.
|
|
# Job-level 'if' does not support env context, so EFFECTIVE_WORKING_DIR is
|
|
# unavailable; must use inputs directly and match both forms: short dropdown
|
|
# names (workflow_dispatch, e.g. 'core') and full 'libs/' paths
|
|
# (workflow_call / working-directory-override).
|
|
if: >-
|
|
contains(fromJSON('["core","langchain_v1"]'),
|
|
inputs.working-directory-override || inputs.working-directory) ||
|
|
startsWith(inputs.working-directory-override || inputs.working-directory,
|
|
'libs/core') || startsWith(inputs.working-directory-override ||
|
|
inputs.working-directory, 'libs/langchain_v1')
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
python-version: [ "3.11", "3.13" ]
|
|
package:
|
|
- name: deepagents
|
|
repo: langchain-ai/deepagents
|
|
path: libs/deepagents
|
|
# No API keys needed for now - deepagents `make test` only runs unit tests
|
|
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
|
|
with:
|
|
path: langchain
|
|
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
|
|
with:
|
|
repository: ${{ matrix.package.repo }}
|
|
path: ${{ matrix.package.name }}
|
|
|
|
- name: Set up Python + uv
|
|
uses: "./langchain/.github/actions/uv_setup"
|
|
with:
|
|
python-version: ${{ matrix.python-version }}
|
|
enable-cache: "false"
|
|
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
with:
|
|
name: dist
|
|
path: dist/
|
|
|
|
- name: Install ${{ matrix.package.name }} with local packages
|
|
# External dependents don't have [tool.uv.sources] pointing to this repo,
|
|
# so we install the package normally then override with the built wheel.
|
|
env:
|
|
PRERELEASE_FLAG: ${{ inputs.allow-prereleases && '--prerelease=allow' || '' }}
|
|
run: |
|
|
cd ${{ matrix.package.name }}/${{ matrix.package.path }}
|
|
|
|
# Install the package with test dependencies
|
|
uv sync --group test
|
|
|
|
# Override with the built wheel from this release
|
|
uv pip install $PRERELEASE_FLAG $GITHUB_WORKSPACE/dist/*.whl
|
|
|
|
- name: Run ${{ matrix.package.name }} tests
|
|
run: |
|
|
cd ${{ matrix.package.name }}/${{ matrix.package.path }}
|
|
make test
|
|
|
|
publish:
|
|
name: 🚀 Publish to PyPI
|
|
# Publishes the package to PyPI
|
|
needs:
|
|
- build
|
|
- release-notes
|
|
- test-pypi-publish
|
|
- pre-release-checks
|
|
- test-dependents
|
|
- test-prior-published-packages-against-new-core
|
|
# Run if all needed jobs succeeded or were skipped (test-dependents and
|
|
# test-prior-published-packages-against-new-core only run for core/langchain_v1)
|
|
if: ${{ !cancelled() && !failure() }}
|
|
environment: Release
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
# This permission is used for trusted publishing:
|
|
# https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
|
|
#
|
|
# Trusted publishing has to also be configured on PyPI for each package:
|
|
# https://docs.pypi.org/trusted-publishers/adding-a-publisher/
|
|
id-token: write
|
|
|
|
defaults:
|
|
run:
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
|
|
|
|
- name: Set up Python + uv
|
|
uses: "./.github/actions/uv_setup"
|
|
with:
|
|
python-version: ${{ env.PYTHON_VERSION }}
|
|
enable-cache: "false"
|
|
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
with:
|
|
name: dist
|
|
path: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/
|
|
|
|
- name: Publish package distributions to PyPI
|
|
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1
|
|
with:
|
|
packages-dir: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/
|
|
verbose: true
|
|
print-hash: true
|
|
# Temp workaround since attestations are on by default as of gh-action-pypi-publish v1.11.0
|
|
attestations: false
|
|
|
|
mark-release:
|
|
name: 🏷️ Tag GitHub release
|
|
# Marks the GitHub release with the new version tag
|
|
needs:
|
|
- build
|
|
- release-notes
|
|
- test-pypi-publish
|
|
- pre-release-checks
|
|
- publish
|
|
# Run if all needed jobs succeeded or were skipped
|
|
if: ${{ !cancelled() && !failure() }}
|
|
environment: Release
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
# This permission is needed by `ncipollo/release-action` to
|
|
# create the GitHub release/tag
|
|
contents: write
|
|
|
|
defaults:
|
|
run:
|
|
working-directory: ${{ env.EFFECTIVE_WORKING_DIR }}
|
|
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
|
|
|
|
- name: Set up Python + uv
|
|
uses: "./.github/actions/uv_setup"
|
|
with:
|
|
python-version: ${{ env.PYTHON_VERSION }}
|
|
enable-cache: "false"
|
|
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
|
|
with:
|
|
name: dist
|
|
path: ${{ env.EFFECTIVE_WORKING_DIR }}/dist/
|
|
|
|
- name: Create Tag
|
|
uses: ncipollo/release-action@339a81892b84b4eeb0f6e744e4574d79d0d9b8dd # v1
|
|
with:
|
|
# JS actions ignore `defaults.run.working-directory`, so this glob is
|
|
# resolved from the repo root. Point it at the package's `dist/`
|
|
# (where `download-artifact` placed the wheels) instead of a bare
|
|
# `dist/*`, which never matched and attached no assets to releases.
|
|
artifacts: "${{ env.EFFECTIVE_WORKING_DIR }}/dist/*"
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
generateReleaseNotes: false
|
|
tag: ${{needs.build.outputs.pkg-name}}==${{ needs.build.outputs.version }}
|
|
body: ${{ needs.release-notes.outputs.release-body }}
|
|
commit: ${{ github.sha }}
|
|
makeLatest: ${{ needs.build.outputs.pkg-name == 'langchain-core'}}
|