From aa875cb582332a5c8df9f19482cf4aa1aa69dc38 Mon Sep 17 00:00:00 2001 From: Robert Gordon Date: Wed, 30 Sep 2026 10:39:55 +0100 Subject: [PATCH] ci: Fail a release whose tag doesn't match the pom version The first v2.4.0 run built the pom's 2.3.0. Signing was also broken, so nothing shipped. Had it worked, the v2.4.0 code would have gone to Central as 2.3.0, and Central releases can't be deleted. The check only runs on release events, so a manual run still publishes whatever version the pom has. A leading v on the tag is optional. Same step as mailerlite/mailerlite-java#18. Co-Authored-By: Claude Opus 5.5 (1M context) --- .github/workflows/publish.yaml | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index 80741db..bfb46f3 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -20,6 +20,15 @@ jobs: gpg-private-key: ${{ secrets.MAVEN_GPG_PRIVATE_KEY }} # Value of the GPG private key to import gpg-passphrase: MAVEN_GPG_PASSPHRASE # env variable for GPG private key passphrase + - name: Check release tag matches pom version + if: github.event_name == 'release' + run: | + VERSION=$(mvn -q help:evaluate -Dexpression=project.version -DforceStdout) + if [ "${GITHUB_REF_NAME#v}" != "$VERSION" ]; then + echo "::error::Release tag $GITHUB_REF_NAME does not match pom version $VERSION" + exit 1 + fi + - name: Publish to Apache Maven Central run: mvn clean deploy env: