From bd26aa0272fbceea64f4445c58fbcab30777aeca Mon Sep 17 00:00:00 2001 From: Mitsunori Komatsu Date: Sun, 27 Sep 2026 17:10:04 +0900 Subject: [PATCH 1/3] Publish to Maven Central with JReleaser Replace the vanniktech plugin with maven-publish and JReleaser. Gradle stages the publications in build/staging-deploy, and JReleaser signs them and uploads them to the Central Portal. A v*.*.* tag push runs the new release workflow, which reads the Portal token and GPG key from repository secrets. Also replace the deprecated tasks.registering delegate for generatePackageVersion. --- .github/workflows/release.yml | 33 ++++++++++++++ build.gradle.kts | 86 +++++++++++++++++++++++++---------- gradle/libs.versions.toml | 4 +- 3 files changed, 96 insertions(+), 27 deletions(-) create mode 100644 .github/workflows/release.yml diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..198b7a3 --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,33 @@ +name: Release + +on: + workflow_dispatch: + push: + tags: + - 'v[0-9]+.[0-9]+.[0-9]+' + +jobs: + release: + runs-on: ubuntu-latest + permissions: + contents: write + steps: + - uses: actions/checkout@v5 + with: + fetch-depth: 0 + - uses: actions/setup-java@v5 + with: + distribution: temurin + java-version: '17' + - uses: gradle/actions/setup-gradle@v5 + - name: Build and test + run: ./gradlew build + - name: Publish with JReleaser + run: ./gradlew publishAllPublicationsToStagingRepository jreleaserFullRelease + env: + JRELEASER_GPG_SECRET_KEY: ${{ secrets.MAVEN_CENTRAL_GPG_SECRET_KEY }} + JRELEASER_GPG_PUBLIC_KEY: ${{ secrets.MAVEN_CENTRAL_GPG_PUBLIC_KEY }} + JRELEASER_GPG_PASSPHRASE: ${{ secrets.MAVEN_CENTRAL_GPG_PASSPHRASE }} + JRELEASER_MAVENCENTRAL_SONATYPE_USERNAME: ${{ secrets.MAVEN_CENTRAL_USERNAME }} + JRELEASER_MAVENCENTRAL_SONATYPE_PASSWORD: ${{ secrets.MAVEN_CENTRAL_PASSWORD }} + JRELEASER_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/build.gradle.kts b/build.gradle.kts index 93caf1b..b873f03 100644 --- a/build.gradle.kts +++ b/build.gradle.kts @@ -1,7 +1,10 @@ +import org.jreleaser.model.Active + plugins { id("java-library") id("checkstyle") - alias(libs.plugins.maven.publish) + id("maven-publish") + alias(libs.plugins.jreleaser) } group = "org.komamitsu" @@ -12,6 +15,8 @@ java { toolchain { languageVersion = JavaLanguageVersion.of(17) } + withJavadocJar() + withSourcesJar() } repositories { @@ -31,7 +36,7 @@ dependencies { // PackageVersion.java carries the coordinates and version Jackson reports via Versioned. // Generate it from the Gradle project so it cannot drift from the published POM. val packageDir = "org/komamitsu/jackson/dataformat/msgpack" -val generatePackageVersion by tasks.registering { +val generatePackageVersion = tasks.register("generatePackageVersion") { val outputDir = layout.buildDirectory.dir("generated/sources/packageVersion/java/main") val projectVersion = project.version.toString() val projectGroup = project.group.toString() @@ -128,32 +133,63 @@ checkstyle { maxWarnings = 0 } -mavenPublishing { - publishToMavenCentral() - signAllPublications() - - pom { - name = project.name - description = project.description - url = "https://github.com/komamitsu/jackson-dataformat-msgpack" - licenses { - license { - name = "Apache-2.0" - url = "https://www.apache.org/licenses/LICENSE-2.0.txt" +// Publications are staged locally; JReleaser signs them and uploads them to the Central Portal. +val stagingDir = layout.buildDirectory.dir("staging-deploy") + +publishing { + publications { + create("maven") { + from(components["java"]) + + pom { + name = project.name + description = project.description + url = "https://github.com/komamitsu/jackson-dataformat-msgpack" + licenses { + license { + name = "Apache-2.0" + url = "https://www.apache.org/licenses/LICENSE-2.0.txt" + } + } + developers { + developer { + id = "komamitsu" + name = "Mitsunori Komatsu" + email = "komamitsu@gmail.com" + url = "https://github.com/komamitsu" + } + } + scm { + url = "https://github.com/komamitsu/jackson-dataformat-msgpack" + connection = "scm:git:git://github.com/komamitsu/jackson-dataformat-msgpack.git" + developerConnection = "scm:git:ssh://git@github.com/komamitsu/jackson-dataformat-msgpack.git" + } } } - developers { - developer { - id = "komamitsu" - name = "Mitsunori Komatsu" - email = "komamitsu@gmail.com" - url = "https://github.com/komamitsu" - } + } + repositories { + maven { + name = "staging" + url = uri(stagingDir) } - scm { - url = "https://github.com/komamitsu/jackson-dataformat-msgpack" - connection = "scm:git:git://github.com/komamitsu/jackson-dataformat-msgpack.git" - developerConnection = "scm:git:ssh://git@github.com/komamitsu/jackson-dataformat-msgpack.git" + } +} + +jreleaser { + signing { + pgp { + active = Active.ALWAYS + armored = true + } + } + deploy { + maven { + mavenCentral.create("sonatype") { + active = Active.ALWAYS + url = "https://central.sonatype.com/api/v1/publisher" + applyMavenCentralRules = true + stagingRepository(stagingDir.get().asFile.path) + } } } } diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml index ec06b66..0bd041f 100644 --- a/gradle/libs.versions.toml +++ b/gradle/libs.versions.toml @@ -6,7 +6,7 @@ hamcrest = "3.0" commons-math3 = "3.6.1" jmh = "1.37" jmh-plugin = "0.7.3" -maven-publish-plugin = "0.34.0" +jreleaser = "1.26.0" [libraries] jackson-databind = { module = "tools.jackson.core:jackson-databind", version.ref = "jackson" } @@ -18,4 +18,4 @@ commons-math3 = { module = "org.apache.commons:commons-math3", version.ref = "co [plugins] jmh = { id = "me.champeau.jmh", version.ref = "jmh-plugin" } -maven-publish = { id = "com.vanniktech.maven.publish", version.ref = "maven-publish-plugin" } +jreleaser = { id = "org.jreleaser", version.ref = "jreleaser" } From a24272c76df45b4901264625230f08b7641a2132 Mon Sep 17 00:00:00 2001 From: Mitsunori Komatsu Date: Sun, 27 Sep 2026 17:19:36 +0900 Subject: [PATCH 2/3] Release only from version tags Drop the manual trigger from the release workflow. A manual run could publish whatever branch or commit was selected. A failed tag run can still be retried with Re-run jobs. --- .github/workflows/release.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 198b7a3..afdbd4b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,7 +1,6 @@ name: Release on: - workflow_dispatch: push: tags: - 'v[0-9]+.[0-9]+.[0-9]+' From e31d88e4274dd4e215d689dfd2d85ee3e89628ea Mon Sep 17 00:00:00 2001 From: Mitsunori Komatsu Date: Sun, 27 Sep 2026 17:24:45 +0900 Subject: [PATCH 3/3] Fail the release when the tag and project version differ The published version comes from build.gradle.kts, not from the tag. A tag pushed on a commit that still has a SNAPSHOT or different version would otherwise go on to create a GitHub release for the wrong version. --- .github/workflows/release.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index afdbd4b..8b82c5a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -19,6 +19,13 @@ jobs: distribution: temurin java-version: '17' - uses: gradle/actions/setup-gradle@v5 + - name: Check that the tag matches the project version + run: | + version=$(./gradlew -q properties --property version | sed -n 's/^version: //p') + if [ "v$version" != "$GITHUB_REF_NAME" ]; then + echo "Tag $GITHUB_REF_NAME does not match project version $version" >&2 + exit 1 + fi - name: Build and test run: ./gradlew build - name: Publish with JReleaser