From 1019afa3ff650354d48ab8ddc7eabeabd09c1840 Mon Sep 17 00:00:00 2001 From: Mario Serrano Date: Tue, 22 Sep 2026 10:45:51 -0500 Subject: [PATCH] chore: drop optional SHA256/SHA512 checksums from Maven Central deploy Maven Central only requires MD5 + SHA1 checksums per file (SHA256/SHA512 are accepted but explicitly optional per Sonatype's own publishing requirements doc). central-publishing-maven-plugin defaults to generating all four; set checksums=required to generate only the mandatory two. Per component this drops file count from 24 to 16 for a jar-packaged module (-33%), and from 6 to 4 for a pom-packaged aggregator. Verified against a real deploy log (v26.9.0): jar-packaged modules stage jar/sources.jar/javadoc.jar/pom x 6 files each; pom-packaged aggregators (11 of them) correctly already skip javadoc/sources (maven-javadoc-plugin and maven-source-plugin self-skip for packaging=pom) and only stage pom+asc+checksums -- no waste there, this checksums setting is the only available lever without dropping something Central actually requires (sources.jar/javadoc.jar/.asc signatures/.md5+.sha1 are all mandatory for non-pom packaging). Relevant with Maven Central's new per-organization monthly file-count tracking (soft-limit phase now, enforcement starts Oct 1 2026) -- see https://central.sonatype.org/publish/maven-central-publishing-limits/ Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01UcARdenC1Sk5EVpkzboH9W --- pom.xml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/pom.xml b/pom.xml index 407c5fd1..41934f0f 100644 --- a/pom.xml +++ b/pom.xml @@ -170,6 +170,10 @@ central true + + required