diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 707754d..2890aab 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -70,23 +70,23 @@ jobs: name: python-package-distributions path: dist/ - name: Sign packages - uses: sigstore/gh-action-sigstore-python@v2.1.1 + uses: sigstore/gh-action-sigstore-python@v3.0.0 with: inputs: >- ./dist/*.tar.gz ./dist/*.whl - name: Create GitHub Release env: - GITHUB_TOKEN: ${{ github.token }} + GH_TOKEN: ${{ github.token }} run: >- gh release create - '${{ github.ref_name }}' - --repo '${{ github.repository }}' - --title '${{ github.event.repository.name }} ${{ github.ref_name }}' + "$GITHUB_REF_NAME" + --repo "$GITHUB_REPOSITORY" + --title "${GITHUB_REPOSITORY#*/} $GITHUB_REF_NAME" - name: Upload artifact signatures to GitHub Release env: - GITHUB_TOKEN: ${{ github.token }} + GH_TOKEN: ${{ github.token }} run: >- gh release upload - '${{ github.ref_name }}' dist/** - --repo '${{ github.repository }}' + "$GITHUB_REF_NAME" dist/** + --repo "$GITHUB_REPOSITORY"