Fix Maven Central publishing and sync build with mailersend-java - #18
Merged
Merged
Conversation
setup-java v6 no longer writes the gpg.passphrase server into settings.xml, and maven-gpg-plugin 1.6 only reads the passphrase from there. Moving off setup-java v3 therefore needs gpg 3.2.8, which reads MAVEN_GPG_PASSPHRASE from the environment. Same fix as mailersend-java 16a123d. All plugins now match mailersend-java. The workflow pins checkout v7 and setup-java v6 by SHA, builds on JDK 11 like mailersend, and drops -P release, which named a profile that doesn't exist. A release now fails fast when its tag doesn't match the pom version, the mistake that made mailersend's first v2.4.0 run build 2.3.0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gson 2.8.7 -> 2.13.2 (CVE-2022-25647) and commons-io 2.7 -> 2.21.0 (CVE-2024-47554). junit 5.7.0 -> 5.14.3, plus junit-platform-launcher as mailersend-java has it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Both copied from mailersend-java. The tests replay recorded fixtures, so CI needs no token. testFailureIgnore stays on, as in mailersend, so the check reports results without failing on them. Renovate uses the :base preset. The :app preset from onboarding PR #15 disables the maven manager, so it would never bump the pom. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why?
The publish workflow has never run in this repo. It still uses checkout/setup-java v3 and old Maven plugins, so 0.0.4 has never been released. mailersend-java's publishing broke when it moved to setup-java v6, and mailersend/mailersend-java#141 fixed it by bumping maven-gpg-plugin to 3.2.8. This PR copies that working setup so that publishing a GitHub release puts the version on Maven Central with no manual steps.
Changes
publish.yamlis now mailersend-java's workflow: checkout v7 and setup-java v6 pinned by SHA, JDK 11 instead of 17, and no-P release(that profile doesn't exist). It adds one step, which fails a release whose tag (with or without a leadingv) doesn't match the pom version.pom.xmlplugins are all on mailersend-java's versions. The signing fix is maven-gpg-plugin 1.6 → 3.2.8: setup-java v6 expects the plugin to readMAVEN_GPG_PASSPHRASEfrom the environment, which 3.2.x does and 1.6 doesn't.pom.xmldependencies: gson 2.8.7 → 2.13.2, commons-io 2.7 → 2.21.0, junit 5.7.0 → 5.14.3, plus junit-platform-launcher, as in mailersend-java.test.ymlis copied from mailersend-java and runsmvn teston JDK 11, 17 and 21 for pushes and PRs tomain. The tests replay recorded fixtures, so the job needs no secrets.renovate.jsonuses the org:basepreset, same as mailersend-java. The:apppreset from onboarding PR chore: Configure Renovate #15 turns off the maven manager, so it would never bump the pom.Risks
testFailureIgnorestays on, as in mailersend-java, so the Build check passes even when tests fail. TheTests run:line in each job log is the only place a regression from the gson upgrade will show.Performance impact
None. Only the build and CI config change; the SDK source is untouched.
Security impact
Actions are pinned by commit SHA. The gson and commons-io bumps fix CVE-2022-25647 and CVE-2024-47554. Nothing changes in how the SDK handles credentials or requests.
How to QA
Java 11/17/21 Testjob, then theRun test suitestep. ExpectTests run: 45, Failures: 0, Errors: 0. The check passes regardless, so read this line.v0.0.4onmain. TheMaven Publishrun should pass the tag check, sign withgpg:3.2.8and finish with the deployment published.0.0.4.SDK behaviour doesn't need QA, since no source files changed.
How to release
Merge, then publish a GitHub release tagged
v0.0.4againstmain. Don't use "Run workflow" on Maven Publish as a dry run: a manual run skips the tag check and publishes whatever version the pom has onmain.Rollback strategy
Screenshots, recordings
N/A
I used AI to generate parts of this PR
Yes
🤖 Generated with Claude Code