Publish to Maven Central with JReleaser - #20
Merged
Merged
Conversation
Replace the vanniktech plugin with maven-publish and JReleaser. Gradle stages the publications in build/staging-deploy, and JReleaser signs them and uploads them to the Central Portal. A v*.*.* tag push runs the new release workflow, which reads the Portal token and GPG key from repository secrets. Also replace the deprecated tasks.registering delegate for generatePackageVersion.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The workflow permits unguarded manual publishing, and GitHub release creation is not configured.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Migrates Maven Central publishing to Gradle maven-publish and JReleaser, with automated release workflow support.
Changes:
- Adds the JReleaser plugin.
- Configures staged publications, signing, and Central Portal deployment.
- Adds a tag-triggered release workflow.
| File | Summary | Findings |
|---|---|---|
gradle/libs.versions.toml |
Adds the JReleaser plugin version. | None |
build.gradle.kts |
Configures publications, staging, signing, and deployment. | Moderate: GitHub release provider is not configured. |
.github/workflows/release.yml |
Builds and publishes tagged releases. | Critical: manual dispatch can publish an unintended revision. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Drop the manual trigger from the release workflow. A manual run could publish whatever branch or commit was selected. A failed tag run can still be retried with Re-run jobs.
The published version comes from build.gradle.kts, not from the tag. A tag pushed on a commit that still has a SNAPSHOT or different version would otherwise go on to create a GitHub release for the wrong version.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
maven-publishand JReleaser. Gradle stages the publications inbuild/staging-deploy, and JReleaser signs them and uploads them to the Central Portal.v*.*.*tag push. It builds the project, publishes to Maven Central and creates a GitHub release. Credentials come from repository secrets.tasks.registeringdelegate forgeneratePackageVersion.Testing
./gradlew clean buildpasses.publishAllPublicationsToStagingRepositorystages the jar, sources jar, javadoc jar, POM and Gradle module metadata.jreleaserDeploy --dryrunwith a temporary release version and a throwaway signing key passes the Maven Central POM checks, signs every staged file and builds the upload bundle. Nothing was uploaded.One Gradle deprecation warning remains (
Project.getProperties). It comes from JReleaser's own plugin code, not from this build script.