ci: shared sign-fatjars.sh + cross-repo byte-identical shared files - #160
Merged
bernardladenthin merged 3 commits intoJul 24, 2026
Merged
Conversation
…c pointer Replace the inline gpg detach-sign loop in both publish jobs with the cross-repo shared .github/sign-fatjars.sh (byte-identical with java-llama.cpp): the classifier build loop stays, then all fat jar variants are collected into the asset dir and the shared script signs each in place (ephemeral keyring, verify) — a uniform signing mechanism across the sibling repos instead of two ad-hoc gpg invocations. Also add a "Fat-jar release assets" pointer in CLAUDE.md to the new workspace/policies/fat-jar-release-assets.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TJzCezSnQ8FxpFdeVxYxQY
…cross-repo) Unify the throwaway signing-selftest Gradle project (build.gradle.kts + settings.gradle.kts) to the dual SPDX-License-Identifier "MIT OR Apache-2.0" so the files are TRULY byte-identical across all four sibling repos (java-llama.cpp used MIT, the others Apache-2.0 — same body, only the header drifted). This matches the cross-repo-synced-file convention already used for sign-fatjars.sh and makes the verify-signing-key-gradle preflight project checksum-verifiable via workspace. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TJzCezSnQ8FxpFdeVxYxQY
…al cross-repo) Sync lombok.config to the canonical workspace policy content verbatim The three Lombok repos had IDENTICAL directives but drifted comments (per-repo rationale in the file). Replace each with the canonical block from workspace/policies/lombok-config.md verbatim, so the file is now byte-identical across all three (the rationale lives once in the policy / crossrepo, not in the file). Recorded in the workspace cross-repo checksum drift-check. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TJzCezSnQ8FxpFdeVxYxQY
bernardladenthin
had a problem deploying
to
maven-central
July 24, 2026 06:25 — with
GitHub Actions
Failure
bernardladenthin
had a problem deploying
to
startgate
July 24, 2026 06:25 — with
GitHub Actions
Error
bernardladenthin
had a problem deploying
to
maven-central
July 24, 2026 06:25 — with
GitHub Actions
Failure
bernardladenthin
deleted the
claude/bitcoinaddressfinder-jar-upload-k0tkj7
branch
July 24, 2026 06:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
.github/sign-fatjars.sh(byte-identical with java-llama.cpp) instead of an inlinegpgloop — the classifier build loop stays; the fat jars are collected into the asset dir and signed uniformly. Adds a "Fat-jar release assets" pointer inCLAUDE.md..github/signing-selftest/(build.gradle.kts+settings.gradle.kts) toMIT OR Apache-2.0so the throwawayverify-signing-key-gradleproject is truly byte-identical across all four repos.lombok.configto the canonicalworkspace/policies/lombok-config.mdblock verbatim (directives already identical; only comment rationale drifted).CI-config / docs only — no production code changes. Fat-jar signing runs only on the dispatch-gated publish path.
Test plan
vulkan-linux-x86-6425 MB single-backend)Related issues / PRs
Coordinated cross-repo change; the canonical docs + the checksum drift-check table land in the workspace PR (same branch name). Sibling PRs: java-llama.cpp / BitcoinAddressFinder / streambuffer / workspace. The per-classifier fat-jar wiring shipped earlier in #159; this is the shared-script + consistency follow-up.
Checklist
🤖 Generated with Claude Code
https://claude.ai/code/session_01TJzCezSnQ8FxpFdeVxYxQY
Generated by Claude Code