Skip to content

Fix Maven Central publishing and sync build with mailersend-java - #18

Merged
robgordon89 merged 3 commits into
mainfrom
fix/maven-publish
Sep 30, 2026
Merged

robgordon89 merged 3 commits into
mainfrom
fix/maven-publish

Conversation

@robgordon89

Copy link
Copy Markdown
Contributor

Why?

The publish workflow has never run in this repo. It still uses checkout/setup-java v3 and old Maven plugins, so 0.0.4 has never been released. mailersend-java's publishing broke when it moved to setup-java v6, and mailersend/mailersend-java#141 fixed it by bumping maven-gpg-plugin to 3.2.8. This PR copies that working setup so that publishing a GitHub release puts the version on Maven Central with no manual steps.

Changes

  1. publish.yaml is now mailersend-java's workflow: checkout v7 and setup-java v6 pinned by SHA, JDK 11 instead of 17, and no -P release (that profile doesn't exist). It adds one step, which fails a release whose tag (with or without a leading v) doesn't match the pom version.
  2. pom.xml plugins are all on mailersend-java's versions. The signing fix is maven-gpg-plugin 1.6 → 3.2.8: setup-java v6 expects the plugin to read MAVEN_GPG_PASSPHRASE from the environment, which 3.2.x does and 1.6 doesn't.
  3. pom.xml dependencies: gson 2.8.7 → 2.13.2, commons-io 2.7 → 2.21.0, junit 5.7.0 → 5.14.3, plus junit-platform-launcher, as in mailersend-java.
  4. test.yml is copied from mailersend-java and runs mvn test on JDK 11, 17 and 21 for pushes and PRs to main. The tests replay recorded fixtures, so the job needs no secrets.
  5. renovate.json uses the org :base preset, same as mailersend-java. The :app preset from onboarding PR chore: Configure Renovate #15 turns off the maven manager, so it would never bump the pom.

Risks

  • testFailureIgnore stays on, as in mailersend-java, so the Build check passes even when tests fail. The Tests run: line in each job log is the only place a regression from the gson upgrade will show.
  • Javadoc now builds on JDK 11 with plugin 3.12.0 (it was JDK 17 with 3.0.1). The PR check doesn't build javadoc, so the first build is at release. If it fails there, the build stops before anything is uploaded.
  • gson and commons-io are runtime dependencies, so SDK users get the newer versions through this dependency.
  • If the GPG signing key is new, its public key has to be on a keyserver Central checks (keyserver.ubuntu.com, keys.openpgp.org), or Central rejects the bundle.

Performance impact

None. Only the build and CI config change; the SDK source is untouched.

Security impact

Actions are pinned by commit SHA. The gson and commons-io bumps fix CVE-2022-25647 and CVE-2024-47554. Nothing changes in how the SDK handles credentials or requests.

How to QA

  1. On this PR, open each Java 11/17/21 Test job, then the Run test suite step. Expect Tests run: 45, Failures: 0, Errors: 0. The check passes regardless, so read this line.
  2. After merging, publish a GitHub release with tag v0.0.4 on main. The Maven Publish run should pass the tag check, sign with gpg:3.2.8 and finish with the deployment published.
  3. Check that https://repo1.maven.org/maven2/com/mailerlite/mailerlite-java/maven-metadata.xml lists 0.0.4.

SDK behaviour doesn't need QA, since no source files changed.

How to release

Merge, then publish a GitHub release tagged v0.0.4 against main. Don't use "Run workflow" on Maven Publish as a dry run: a manual run skips the tag check and publishes whatever version the pom has on main.

Rollback strategy

  • Migrations: none.
  • Data changes: none.
  • External dependencies: Maven Central releases can't be changed or deleted. A bad 0.0.4 can only be replaced by releasing 0.0.5.
  • Config: revert this PR to restore the previous workflows and pom.

Screenshots, recordings

N/A

I used AI to generate parts of this PR

Yes

🤖 Generated with Claude Code

robgordon89 and others added 3 commits September 30, 2026 10:26
setup-java v6 no longer writes the gpg.passphrase server into
settings.xml, and maven-gpg-plugin 1.6 only reads the passphrase from
there. Moving off setup-java v3 therefore needs gpg 3.2.8, which reads
MAVEN_GPG_PASSPHRASE from the environment. Same fix as mailersend-java
16a123d.

All plugins now match mailersend-java. The workflow pins checkout v7
and setup-java v6 by SHA, builds on JDK 11 like mailersend, and drops
-P release, which named a profile that doesn't exist.

A release now fails fast when its tag doesn't match the pom version,
the mistake that made mailersend's first v2.4.0 run build 2.3.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gson 2.8.7 -> 2.13.2 (CVE-2022-25647) and commons-io 2.7 -> 2.21.0
(CVE-2024-47554). junit 5.7.0 -> 5.14.3, plus junit-platform-launcher
as mailersend-java has it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Both copied from mailersend-java. The tests replay recorded fixtures,
so CI needs no token. testFailureIgnore stays on, as in mailersend, so
the check reports results without failing on them.

Renovate uses the :base preset. The :app preset from onboarding PR #15
disables the maven manager, so it would never bump the pom.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@robgordon89 robgordon89 self-assigned this Sep 30, 2026
@robgordon89
robgordon89 marked this pull request as ready for review September 30, 2026 09:34
@robgordon89
robgordon89 merged commit c68ded2 into main Sep 30, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant