From 6a9f2aab6a4dc037bdc1303acf4c91d7162455b2 Mon Sep 17 00:00:00 2001 From: Robert Gordon Date: Wed, 30 Sep 2026 10:26:36 +0100 Subject: [PATCH 1/3] fix: Sync Maven publishing with mailersend-java setup-java v6 no longer writes the gpg.passphrase server into settings.xml, and maven-gpg-plugin 1.6 only reads the passphrase from there. Moving off setup-java v3 therefore needs gpg 3.2.8, which reads MAVEN_GPG_PASSPHRASE from the environment. Same fix as mailersend-java 16a123d. All plugins now match mailersend-java. The workflow pins checkout v7 and setup-java v6 by SHA, builds on JDK 11 like mailersend, and drops -P release, which named a profile that doesn't exist. A release now fails fast when its tag doesn't match the pom version, the mistake that made mailersend's first v2.4.0 run build 2.3.0. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/publish.yaml | 17 +++++++++++++---- pom.xml | 16 ++++++++-------- 2 files changed, 21 insertions(+), 12 deletions(-) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 37c5293..bfb46f3 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -7,21 +7,30 @@ jobs: build: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - name: Set up Apache Maven Central - uses: actions/setup-java@v3 + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6 with: # running setup-java again overwrites the settings.xml distribution: "temurin" - java-version: "17" + java-version: "11" server-id: central server-username: MAVEN_USERNAME # env variable for username in deploy server-password: MAVEN_TOKEN # env variable for token in deploy gpg-private-key: ${{ secrets.MAVEN_GPG_PRIVATE_KEY }} # Value of the GPG private key to import gpg-passphrase: MAVEN_GPG_PASSPHRASE # env variable for GPG private key passphrase + - name: Check release tag matches pom version + if: github.event_name == 'release' + run: | + VERSION=$(mvn -q help:evaluate -Dexpression=project.version -DforceStdout) + if [ "${GITHUB_REF_NAME#v}" != "$VERSION" ]; then + echo "::error::Release tag $GITHUB_REF_NAME does not match pom version $VERSION" + exit 1 + fi + - name: Publish to Apache Maven Central - run: mvn clean deploy -P release + run: mvn clean deploy env: MAVEN_USERNAME: ${{ secrets.MAVEN_USERNAME }} MAVEN_TOKEN: ${{ secrets.MAVEN_TOKEN }} diff --git a/pom.xml b/pom.xml index 81675bf..5a5b2f9 100644 --- a/pom.xml +++ b/pom.xml @@ -41,19 +41,19 @@ maven-surefire-plugin - 2.22.2 + 3.5.5 true maven-failsafe-plugin - 2.22.2 + 3.5.5 org.apache.maven.plugins maven-source-plugin - 2.2.1 + 2.4 attach-sources @@ -66,7 +66,7 @@ org.apache.maven.plugins maven-javadoc-plugin - 3.0.1 + 3.12.0 attach-javadocs @@ -79,7 +79,7 @@ org.apache.maven.plugins maven-gpg-plugin - 1.6 + 3.2.8 sign-artifacts @@ -100,17 +100,17 @@ org.apache.maven.plugins maven-site-plugin - 3.7.1 + 3.21.0 org.apache.maven.plugins maven-project-info-reports-plugin - 3.0.0 + 3.9.0 org.sonatype.central central-publishing-maven-plugin - 0.7.0 + 0.10.0 true central From 690f0150572df2e9de4521969098273120254a46 Mon Sep 17 00:00:00 2001 From: Robert Gordon Date: Wed, 30 Sep 2026 10:26:47 +0100 Subject: [PATCH 2/3] chore: Match mailersend-java dependency versions gson 2.8.7 -> 2.13.2 (CVE-2022-25647) and commons-io 2.7 -> 2.21.0 (CVE-2024-47554). junit 5.7.0 -> 5.14.3, plus junit-platform-launcher as mailersend-java has it. Co-Authored-By: Claude Opus 5.5 (1M context) --- pom.xml | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/pom.xml b/pom.xml index 5a5b2f9..67a0f2b 100644 --- a/pom.xml +++ b/pom.xml @@ -125,24 +125,30 @@ org.junit.jupiter junit-jupiter-api - 5.7.0 + 5.14.3 test org.junit.jupiter junit-jupiter-engine - 5.7.0 + 5.14.3 + test + + + org.junit.platform + junit-platform-launcher + 1.14.3 test com.google.code.gson gson - 2.8.7 + 2.13.2 commons-io commons-io - 2.7 + 2.21.0 From c3ab765f1f69afa32b2ef25b35f520ee03e9673e Mon Sep 17 00:00:00 2001 From: Robert Gordon Date: Wed, 30 Sep 2026 10:26:48 +0100 Subject: [PATCH 3/3] ci: Add test workflow and Renovate config Both copied from mailersend-java. The tests replay recorded fixtures, so CI needs no token. testFailureIgnore stays on, as in mailersend, so the check reports results without failing on them. Renovate uses the :base preset. The :app preset from onboarding PR #15 disables the maven manager, so it would never bump the pom. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/test.yml | 30 ++++++++++++++++++++++++++++++ renovate.json | 3 +++ 2 files changed, 33 insertions(+) create mode 100644 .github/workflows/test.yml create mode 100644 renovate.json diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml new file mode 100644 index 0000000..577d2e1 --- /dev/null +++ b/.github/workflows/test.yml @@ -0,0 +1,30 @@ +name: Build + +on: + push: + branches: [ main ] + pull_request: + branches: [ main ] + +jobs: + run: + + runs-on: ubuntu-24.04 + strategy: + matrix: + operating-system: [ubuntu-24.04] + java-versions: ['11', '17', '21'] + name: Java ${{ matrix.java-versions }} Test on ${{ matrix.operating-system }} + + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + + - name: Set up JDK ${{ matrix.java-versions }} + uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6 + with: + distribution: 'temurin' + java-version: ${{ matrix.java-versions }} + cache: 'maven' + + - name: Run test suite + run: mvn test diff --git a/renovate.json b/renovate.json new file mode 100644 index 0000000..1302680 --- /dev/null +++ b/renovate.json @@ -0,0 +1,3 @@ +{ + "extends": ["github>mailerlite/renovate-config:base"] +}