Releasing to PyPI¶
Releases publish one Python 3.10+ abi3 wheel per platform for Linux x86-64
and arm64, macOS Apple Silicon and Intel, and Windows x86-64, plus a source
distribution. The package metadata currently limits installation to CPython
3.10–3.14. Each platform's wheel is smoke-tested on Python 3.10, 3.12, and
3.14 before publication.
The release workflow
builds distributions on the five corresponding GitHub runners.
Trusted-publisher setup¶
The polars-tokenizer PyPI project was created by the v0.1.0 release. Its
trusted publisher is already configured with these values:
| Field | Value |
|---|---|
| PyPI project name | polars-tokenizer |
| GitHub owner | diegoglozano |
| Repository | polars-tokenizer |
| Workflow filename | release.yml |
| Environment | pypi |
The GitHub repository has a pypi environment restricted to v* tags.
Configure required reviewers there if releases should need an explicit approval. Trusted
publishing uses a short-lived GitHub OIDC identity; do not add a long-lived
PyPI token to repository secrets. When setting up a new project or fork, a
pending publisher does not reserve the project name until the first upload
succeeds.
Preflight¶
- Update both
pyproject.tomlandCargo.tomlto the same new version. RefreshCargo.lockanduv.lockif needed. PyPI files and versions cannot be overwritten, so verify the version has not already been published. -
Run the normal CI checks and build a local wheel and source distribution:
-
Merge the release changes to
main. Use Run workflow on the GitHub Release workflow to build the cross-platform artifacts without uploading anything. Check that all fiveabi3wheels, the source distribution, and cross-version wheel smoke-test jobs succeed. - Create and publish a GitHub Release tagged
vX.Y.Zon the verifiedmaincommit. The tag must match the Python and Rust package versions. Publishing the GitHub Release triggers the same builds, then the isolatedpypienvironment job uploads the artifacts. Prereleases do not upload. - Check the PyPI file list, install a published wheel in a clean environment, and run a small token-count expression before announcing the release.
The workflow rejects mismatched Python/Rust versions, a release tag that does
not match the package version, and release commits not reachable from main.
The publish job has OIDC permission but does not check out source or build code.
For PyPI's account-side setup and security details, see the pending publisher guide and publishing guide.