forked from spotify/fmt-maven-plugin
-
Notifications
You must be signed in to change notification settings - Fork 0
131 lines (115 loc) · 5.13 KB
/
Copy pathrelease.yml
File metadata and controls
131 lines (115 loc) · 5.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
name: Release
# Tags only, and the tag is the version: the POM keeps its development version, and this workflow sets
# the tag's before it builds. A release is four numbers, X.Y.Z.N; anything else is refused.
#
# Maven Central first. The build stages the plugin with its sources and javadoc in target/staging-deploy,
# and JReleaser signs it with the release key, uploads it to the Central Portal and publishes it once the
# Portal has validated it. Then a draft GitHub release on the tag gets the same jar, signed, with a
# checksum file and the commits since the previous tag; publishing the draft is a click on GitHub.
#
# Needs four repository secrets: JRELEASER_MAVENCENTRAL_USERNAME and JRELEASER_MAVENCENTRAL_PASSWORD (the
# Central Portal user token), JRELEASER_GPG_SECRET_KEY and JRELEASER_GPG_PASSPHRASE. `mise run gh:secrets`
# sets them from 1Password. The draft release uses the workflow's own GITHUB_TOKEN.
on:
push:
tags:
- '*'
permissions:
contents: read
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
central:
name: Maven Central
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Install JDK 21
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
with:
distribution: temurin
java-version: '21'
- name: Take the version from the tag
env:
VERSION: ${{ github.ref_name }}
run: |
if ! [[ "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "::error::Refusing to release '$VERSION': a release tag is X.Y.Z.N"
exit 1
fi
mvn --no-transfer-progress -B org.codehaus.mojo:versions-maven-plugin:2.22.0:set \
-DnewVersion="$VERSION" -DgenerateBackupPoms=false
- name: Build, test and stage
run: mvn --no-transfer-progress -B deploy -DaltDeploymentRepository=local::file:target/staging-deploy
- name: Sign, upload and publish
run: mvn --no-transfer-progress -B jreleaser:deploy
env:
JRELEASER_DEPLOY_MAVEN_MAVENCENTRAL_SONATYPE_USERNAME: ${{ secrets.JRELEASER_MAVENCENTRAL_USERNAME }}
JRELEASER_DEPLOY_MAVEN_MAVENCENTRAL_SONATYPE_PASSWORD: ${{ secrets.JRELEASER_MAVENCENTRAL_PASSWORD }}
JRELEASER_GPG_SECRET_KEY: ${{ secrets.JRELEASER_GPG_SECRET_KEY }}
JRELEASER_GPG_PASSPHRASE: ${{ secrets.JRELEASER_GPG_PASSPHRASE }}
# The jar Maven Central got, so that the GitHub release carries the same file instead of a rebuild.
- name: Hand the jar to the GitHub release job
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: plugin-jar
path: target/fmt-maven-plugin-${{ github.ref_name }}.jar
if-no-files-found: error
retention-days: 1
- name: Keep JReleaser's log
if: ${{ failure() }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: jreleaser-log
path: target/jreleaser/trace.log
if-no-files-found: ignore
retention-days: 7
# A draft GitHub release on the tag, only once the plugin is on Maven Central. JReleaser signs the jar
# again with the release key and adds a checksum file and the commits since the previous tag. A re-run
# fails while a release for the tag exists.
github-release:
name: draft GitHub release
needs: central
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Install JDK 21
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
with:
distribution: temurin
java-version: '21'
# The central job has already refused anything but a clean X.Y.Z.N.
- name: Take the version from the tag
env:
VERSION: ${{ github.ref_name }}
run: >-
mvn --no-transfer-progress -B org.codehaus.mojo:versions-maven-plugin:2.22.0:set
-DnewVersion="$VERSION" -DgenerateBackupPoms=false
- name: Collect the jar Maven Central got
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: plugin-jar
path: target
- name: Open the draft release
run: mvn --no-transfer-progress -B -P github-release jreleaser:release
env:
JRELEASER_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
JRELEASER_GPG_SECRET_KEY: ${{ secrets.JRELEASER_GPG_SECRET_KEY }}
JRELEASER_GPG_PASSPHRASE: ${{ secrets.JRELEASER_GPG_PASSPHRASE }}
- name: Keep JReleaser's log
if: ${{ failure() }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: jreleaser-log-github
path: target/jreleaser/trace.log
if-no-files-found: ignore
retention-days: 7