Skip to content

ci: open the nightly PRs as the riseproject-dev github app #21

ci: open the nightly PRs as the riseproject-dev github app

ci: open the nightly PRs as the riseproject-dev github app #21

Workflow file for this run

# SPDX-FileCopyrightText: 2026 The RISE Project
# SPDX-License-Identifier: MIT
---
# Based on upstream's wheel builder:
# https://github.com/pyca/bcrypt/blob/5.0.0/.github/workflows/wheel-builder.yml
# bcrypt is a PyO3/Rust extension built with setuptools-rust (not maturin): abi3
# is opt-in via a bdist_wheel flag, not a pyproject/Cargo feature - see build_abi3.
name: Build bcrypt wheels (riscv64)
on:
workflow_dispatch:
inputs:
version:
description: 'Version glob to (re)build; empty builds every version of docs/packages/bcrypt.yaml not released yet'
required: false
default: ''
pull_request:
branches: [main]
paths:
- '.github/workflows/build-bcrypt.yml'
- 'docs/packages/bcrypt.yaml'
push:
branches: [main]
paths:
- '.github/workflows/build-bcrypt.yml'
- 'docs/packages/bcrypt.yaml'
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
cancel-in-progress: true
permissions:
contents: read # to fetch code (actions/checkout)
env:
MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64
# abi3 floor: cp312 is RISE's min Python, so the one wheel loads on >=3.12.
ABI3_FLOOR: cp312
jobs:
setup:
uses: $/.github/workflows/_setup.yml
with:
package: bcrypt
version: ${{ inputs.version }}
build_sdist:
needs: [setup]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
name: Build bcrypt ${{ matrix.version }} sdist
runs-on: ubuntu-latest
env:
BCRYPT_VERSION: ${{ matrix.version }}
steps:
- name: Checkout bcrypt ${{ env.BCRYPT_VERSION }}
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: pyca/bcrypt
ref: ${{ env.BCRYPT_VERSION }}
persist-credentials: false
- name: Install Python
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: '3.12'
activate-environment: true
enable-cache: false
- name: Build sdist
id: sdist
run: |
set -euo pipefail
rm -rf dist
uv pip install build twine
python -m build --sdist --outdir dist
twine check dist/*
- name: Upload sdist artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: bcrypt-${{ env.BCRYPT_VERSION }}-sdist
path: dist/*.tar.gz
if-no-files-found: error
# One cp312-abi3 wheel: cibuildwheel builds it once and reuses+tests it on
# cp313/cp314 (find_compatible_wheel), so all three tags share one wheel.
build_abi3:
needs: [setup, build_sdist]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
name: Build bcrypt ${{ matrix.version }} cp312-abi3-manylinux_riscv64
runs-on: ubuntu-24.04-riscv
timeout-minutes: 90
env:
BCRYPT_VERSION: ${{ matrix.version }}
steps:
- name: Download sdist
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: bcrypt-${{ env.BCRYPT_VERSION }}-sdist
path: dist/
- id: sdist_path
run: echo "path=$(echo dist/*.tar.gz)" >> "$GITHUB_OUTPUT"
- name: Build and test wheel
uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0
with:
package-dir: ${{ steps.sdist_path.outputs.path }}
env:
CIBW_ARCHS: riscv64
CIBW_BUILD: 'cp312-* cp313-* cp314-*'
CIBW_SKIP: '*-musllinux_*' # rustup.rs has no riscv64 musl toolchain
CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }}
# setuptools-rust emits abi3 only when bdist_wheel gets --py-limited-api
# (cibuildwheel won't); without this it's per-interpreter wheels, not abi3.
CIBW_CONFIG_SETTINGS: --build-option=--py-limited-api=${{ env.ABI3_FLOOR }}
# No Rust in the manylinux image; install it and put cargo on PATH.
CIBW_BEFORE_ALL_LINUX: >-
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
CIBW_ENVIRONMENT: 'PATH="$PATH:$HOME/.cargo/bin"'
# Upstream's suite; {package} is the extracted sdist dir (gotcha 5).
CIBW_TEST_REQUIRES: pytest
CIBW_TEST_COMMAND: pytest -q {package}/tests
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: bcrypt-${{ env.BCRYPT_VERSION }}-cp312-abi3-manylinux_riscv64
path: ./wheelhouse/*.whl
if-no-files-found: error
# Free-threaded wheel: per-interpreter, no abi3 (pyo3 disables abi3 under
# Py_GIL_DISABLED). Only cp314t - the riscv64 image has no cp313t interpreter.
build_freethreaded:
needs: [setup, build_sdist]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
name: Build bcrypt ${{ matrix.version }} cp314t-manylinux_riscv64
runs-on: ubuntu-24.04-riscv
timeout-minutes: 90
env:
BCRYPT_VERSION: ${{ matrix.version }}
steps:
- name: Download sdist
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: bcrypt-${{ env.BCRYPT_VERSION }}-sdist
path: dist/
- id: sdist_path
run: echo "path=$(echo dist/*.tar.gz)" >> "$GITHUB_OUTPUT"
- name: Build and test wheel
uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0
with:
package-dir: ${{ steps.sdist_path.outputs.path }}
env:
CIBW_ARCHS: riscv64
CIBW_BUILD: 'cp314t-*' # no --py-limited-api: abi3 has no free-threaded ABI
CIBW_SKIP: '*-musllinux_*'
CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }}
CIBW_BEFORE_ALL_LINUX: >-
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
CIBW_ENVIRONMENT: 'PATH="$PATH:$HOME/.cargo/bin"'
CIBW_TEST_REQUIRES: pytest
CIBW_TEST_COMMAND: pytest -q {package}/tests
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: bcrypt-${{ env.BCRYPT_VERSION }}-cp314t-manylinux_riscv64
path: ./wheelhouse/*.whl
if-no-files-found: error
publish:
name: Publish bcrypt ${{ matrix.version }}
needs: [setup, build_sdist, build_abi3, build_freethreaded]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
permissions:
contents: write
pull-requests: write
uses: $/.github/workflows/_publish-wheel.yml
secrets:
app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }}
with:
artifact-pattern: bcrypt-${{ matrix.version }}-*-manylinux_riscv64