11name : Release
22
3- # Tags only, and the tag is the version: the build reads it from GITHUB_REF_NAME and jreleaserDeploy
4- # refuses anything that is not a clean X.Y.Z or X.Y.Z.N.
3+ # Tags only, and the tag is the version: the build reads it from GITHUB_REF_NAME, and jreleaserDeploy and
4+ # publishPlugins refuse anything that is not a clean X.Y.Z or X.Y.Z.N.
55#
66# Two deployments per tag, because a published groupId:artifactId:version can never gain files
7- # afterwards: the jars go up as one, and every platform's native binary as another. Both are uploaded
8- # and validated only — the Portal holds them until someone presses publish.
7+ # afterwards: the jars go up as one, and every platform's native binary as another. Each is uploaded and
8+ # validated first, and the publish job publishes both only once both are in. A version whose native build
9+ # fails publishes nothing, and its deployments can be dropped in the Portal.
910#
10- # After both, a draft GitHub release on the tag collects the runnable jar, the IDE plugins and the native
11- # binaries.
11+ # Once Maven Central serves both, the Gradle plugins go to the Gradle Plugin Portal. After publishing, a
12+ # draft GitHub release on the tag collects the runnable jar, the IDE plugins and the native binaries.
1213#
13- # Needs four repository secrets: JRELEASER_MAVENCENTRAL_USERNAME and JRELEASER_MAVENCENTRAL_PASSWORD
14- # (the Central Portal user token) plus JRELEASER_GPG_SECRET_KEY and JRELEASER_GPG_PASSPHRASE. The draft
15- # release uses the workflow's own GITHUB_TOKEN.
14+ # Needs six repository secrets: JRELEASER_MAVENCENTRAL_USERNAME and JRELEASER_MAVENCENTRAL_PASSWORD (the
15+ # Central Portal user token), JRELEASER_GPG_SECRET_KEY and JRELEASER_GPG_PASSPHRASE, and
16+ # GRADLE_PUBLISH_KEY and GRADLE_PUBLISH_SECRET (the Gradle Plugin Portal key). The draft release uses the
17+ # workflow's own GITHUB_TOKEN.
1618on :
1719 push :
1820 tags :
2931 jars :
3032 name : jars
3133 runs-on : ubuntu-latest
34+ outputs :
35+ deployment-id : ${{ steps.deployment.outputs.id }}
3236 steps :
3337 - uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
3438 with :
4852 JRELEASER_GPG_SECRET_KEY : ${{ secrets.JRELEASER_GPG_SECRET_KEY }}
4953 JRELEASER_GPG_PASSPHRASE : ${{ secrets.JRELEASER_GPG_PASSPHRASE }}
5054
55+ - name : Hand the deployment to the publish job
56+ id : deployment
57+ run : |
58+ id="$(sed -n 's/^deployMavenCentralSonatypeDeploymentId=//p' build/jreleaser/output.properties)"
59+ if [ -z "$id" ]; then
60+ echo "No deployment ID in build/jreleaser/output.properties"
61+ exit 1
62+ fi
63+ echo "id=$id" >> "$GITHUB_OUTPUT"
64+
5165 - name : Keep JReleaser's log
5266 if : ${{ failure() }}
5367 uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
@@ -121,6 +135,8 @@ jobs:
121135 name : native deploy
122136 needs : native-images
123137 runs-on : ubuntu-latest
138+ outputs :
139+ deployment-id : ${{ steps.deployment.outputs.id }}
124140 steps :
125141 - uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
126142 with :
@@ -144,7 +160,7 @@ jobs:
144160 - name : Show what was collected
145161 run : ls -l native-images
146162
147- # No GraalVM here: nothing is compiled, the binaries are published exactly as they arrived.
163+ # No GraalVM here: nothing is compiled, the binaries are uploaded exactly as they arrived.
148164 - name : Stage, sign and upload the native images
149165 run : ./gradlew -PreleaseTarget=native -PnativeImages=native-images jreleaserDeploy
150166 env :
@@ -153,6 +169,16 @@ jobs:
153169 JRELEASER_GPG_SECRET_KEY : ${{ secrets.JRELEASER_GPG_SECRET_KEY }}
154170 JRELEASER_GPG_PASSPHRASE : ${{ secrets.JRELEASER_GPG_PASSPHRASE }}
155171
172+ - name : Hand the deployment to the publish job
173+ id : deployment
174+ run : |
175+ id="$(sed -n 's/^deployMavenCentralSonatypeDeploymentId=//p' build/jreleaser/output.properties)"
176+ if [ -z "$id" ]; then
177+ echo "No deployment ID in build/jreleaser/output.properties"
178+ exit 1
179+ fi
180+ echo "id=$id" >> "$GITHUB_OUTPUT"
181+
156182 - name : Keep JReleaser's log
157183 if : ${{ failure() }}
158184 uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
@@ -162,13 +188,92 @@ jobs:
162188 if-no-files-found : ignore
163189 retention-days : 7
164190
191+ # Both deployments are uploaded and validated by now. Publishing one is a JReleaser run given its ID,
192+ # which builds nothing. One leg per deployment, so that a re-run repeats only the leg that failed.
193+ publish :
194+ name : publish (${{ matrix.deployment }})
195+ needs : [jars, native-deploy]
196+ runs-on : ubuntu-latest
197+ strategy :
198+ matrix :
199+ include :
200+ - deployment : jars
201+ id : ${{ needs.jars.outputs.deployment-id }}
202+ - deployment : native
203+ id : ${{ needs.native-deploy.outputs.deployment-id }}
204+ steps :
205+ - uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
206+ with :
207+ fetch-depth : 0
208+
209+ - name : Install JDK 21
210+ uses : actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
211+ with :
212+ distribution : temurin
213+ java-version : ' 21'
214+
215+ - name : Publish the deployment
216+ run : ./gradlew jreleaserDeploy
217+ env :
218+ JRELEASER_MAVENCENTRAL_DEPLOYMENT_ID : ${{ matrix.id }}
219+ JRELEASER_DEPLOY_MAVEN_MAVENCENTRAL_SONATYPE_USERNAME : ${{ secrets.JRELEASER_MAVENCENTRAL_USERNAME }}
220+ JRELEASER_DEPLOY_MAVEN_MAVENCENTRAL_SONATYPE_PASSWORD : ${{ secrets.JRELEASER_MAVENCENTRAL_PASSWORD }}
221+ JRELEASER_GPG_SECRET_KEY : ${{ secrets.JRELEASER_GPG_SECRET_KEY }}
222+ JRELEASER_GPG_PASSPHRASE : ${{ secrets.JRELEASER_GPG_PASSPHRASE }}
223+
224+ - name : Keep JReleaser's log
225+ if : ${{ failure() }}
226+ uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
227+ with :
228+ name : jreleaser-log-publish-${{ matrix.deployment }}
229+ path : build/jreleaser/trace.log
230+ if-no-files-found : ignore
231+ retention-days : 7
232+
233+ # The plugins depend on the version's jars and native images, so they go up only once Maven Central
234+ # serves both, which takes some minutes after the publish job. The Gradle Plugin Portal never takes a
235+ # version back.
236+ gradle-plugins :
237+ name : Gradle plugins
238+ needs : publish
239+ runs-on : ubuntu-latest
240+ timeout-minutes : 90
241+ steps :
242+ - uses : actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
243+ with :
244+ fetch-depth : 0
245+
246+ - name : Install JDK 21
247+ uses : actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
248+ with :
249+ distribution : temurin
250+ java-version : ' 21'
251+
252+ - name : Wait for Maven Central to serve the version
253+ env :
254+ VERSION : ${{ github.ref_name }}
255+ run : |
256+ for artifact in open-java-format open-java-format-native; do
257+ url="https://repo1.maven.org/maven2/dev/openjavaformat/${artifact}/${VERSION}/${artifact}-${VERSION}.pom"
258+ until curl --silent --fail --head --output /dev/null "$url"; do
259+ echo "Waiting for ${url}"
260+ sleep 30
261+ done
262+ done
263+
264+ - name : Publish the Gradle plugins
265+ run : ./gradlew :gradle-open-java-format:publishPlugins
266+ env :
267+ GRADLE_PUBLISH_KEY : ${{ secrets.GRADLE_PUBLISH_KEY }}
268+ GRADLE_PUBLISH_SECRET : ${{ secrets.GRADLE_PUBLISH_SECRET }}
269+
165270 # What Maven Central does not carry — the runnable formatter jar, the IntelliJ plugin zip, the Eclipse
166271 # plugin jar, and every platform's native binary as a plain download — goes into a draft GitHub release
167- # on the tag, each file signed with the release key. Only once both deployments are in ; publishing the
168- # draft is a click on GitHub, and a re-run fails while a release for the tag exists.
272+ # on the tag, each file signed with the release key. Only once both deployments are published ; publishing
273+ # the draft is a click on GitHub, and a re-run fails while a release for the tag exists.
169274 github-release :
170275 name : draft GitHub release
171- needs : [jars, native-deploy]
276+ needs : publish
172277 runs-on : ubuntu-latest
173278 permissions :
174279 contents : write
0 commit comments