Skip to content

Commit 8d3107e

Browse files
committed
Upload the IntelliJ plugin unsigned
The Marketplace signs every upload with the JetBrains key, and the check of the author's key against the profile is not available yet, so a signature of our own buys nothing today. It can come back with a signing block in the plugin's build script and three secrets when it is wanted.
1 parent e673437 commit 8d3107e

3 files changed

Lines changed: 9 additions & 28 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 6 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -10,15 +10,13 @@ name: Release
1010
#
1111
# Once Maven Central serves both, the Gradle plugins go to the Gradle Plugin Portal, signed with the same
1212
# release key, and the IntelliJ plugin goes to the JetBrains Marketplace, verified against the IDEs it
13-
# supports and signed with a key of its own. After publishing, a draft GitHub release on the tag collects the
14-
# runnable jar, the Gradle and IDE plugins and the native binaries.
13+
# supports first. After publishing, a draft GitHub release on the tag collects the runnable jar, the Gradle
14+
# and IDE plugins and the native binaries.
1515
#
16-
# Needs ten repository secrets: JRELEASER_MAVENCENTRAL_USERNAME and JRELEASER_MAVENCENTRAL_PASSWORD (the
16+
# Needs seven repository secrets: JRELEASER_MAVENCENTRAL_USERNAME and JRELEASER_MAVENCENTRAL_PASSWORD (the
1717
# Central Portal user token), JRELEASER_GPG_SECRET_KEY and JRELEASER_GPG_PASSPHRASE, GRADLE_PUBLISH_KEY and
18-
# GRADLE_PUBLISH_SECRET (the Gradle Plugin Portal key), JETBRAINS_MARKETPLACE_TOKEN (a permanent token of
19-
# the Marketplace account that owns the plugin), and JETBRAINS_CERTIFICATE_CHAIN, JETBRAINS_PRIVATE_KEY and
20-
# JETBRAINS_PRIVATE_KEY_PASSWORD (the plugin signing key; without them the zip goes up unsigned). The draft
21-
# release uses the workflow's own GITHUB_TOKEN.
18+
# GRADLE_PUBLISH_SECRET (the Gradle Plugin Portal key) and JETBRAINS_MARKETPLACE_TOKEN (a permanent token of
19+
# the Marketplace account that owns the plugin). The draft release uses the workflow's own GITHUB_TOKEN.
2220
on:
2321
push:
2422
tags:
@@ -307,13 +305,10 @@ jobs:
307305
if-no-files-found: ignore
308306
retention-days: 7
309307

310-
- name: Sign and upload the plugin
308+
- name: Upload the plugin
311309
run: ./gradlew :open-java-format-idea-plugin:publishPlugin
312310
env:
313311
JETBRAINS_MARKETPLACE_TOKEN: ${{ secrets.JETBRAINS_MARKETPLACE_TOKEN }}
314-
JETBRAINS_CERTIFICATE_CHAIN: ${{ secrets.JETBRAINS_CERTIFICATE_CHAIN }}
315-
JETBRAINS_PRIVATE_KEY: ${{ secrets.JETBRAINS_PRIVATE_KEY }}
316-
JETBRAINS_PRIVATE_KEY_PASSWORD: ${{ secrets.JETBRAINS_PRIVATE_KEY_PASSWORD }}
317312

318313
# What Maven Central does not carry — the runnable formatter jar, the Gradle plugins' jar, the IntelliJ
319314
# plugin zip, the Eclipse plugin jar, and every platform's native binary as a plain download — goes into

‎mise.toml‎

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -86,11 +86,6 @@ apply GRADLE_PUBLISH_KEY 'op://Private/open-java-format/GitHub/GRADLE_PUBLISH_KE
8686
apply GRADLE_PUBLISH_SECRET 'op://Private/open-java-format/GitHub/GRADLE_PUBLISH_SECRET' actions
8787
8888
# What release.yml uploads the IntelliJ plugin to the JetBrains Marketplace with: a permanent token of the
89-
# Marketplace account that owns the plugin, and the key the zip is signed with before the Marketplace adds
90-
# its own signature. The chain and the key are the PEM files as they are, line breaks included; the key
91-
# stays encrypted with the password.
89+
# Marketplace account that owns the plugin.
9290
apply JETBRAINS_MARKETPLACE_TOKEN 'op://Private/open-java-format/GitHub/JETBRAINS_MARKETPLACE_TOKEN' actions
93-
apply JETBRAINS_CERTIFICATE_CHAIN 'op://Private/open-java-format/GitHub/JETBRAINS_CERTIFICATE_CHAIN' actions
94-
apply JETBRAINS_PRIVATE_KEY 'op://Private/open-java-format/GitHub/JETBRAINS_PRIVATE_KEY' actions
95-
apply JETBRAINS_PRIVATE_KEY_PASSWORD 'op://Private/open-java-format/GitHub/JETBRAINS_PRIVATE_KEY_PASSWORD' actions
9691
"""

‎open-java-format-idea-plugin/build.gradle‎

Lines changed: 2 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -106,21 +106,12 @@ intellijPlatform {
106106
// publishPlugin uploads the zip to the JetBrains Marketplace, from the release workflow (see
107107
// .github/workflows/release.yml). The token is a permanent token of the Marketplace account that owns
108108
// the plugin; without it the task fails before uploading anything. The Marketplace never takes a version
109-
// back and rejects a version it already has.
109+
// back and rejects a version it already has. The zip goes up unsigned, and the Marketplace signs it with
110+
// the JetBrains key; a signature of our own would take a `signing { }` block here and three more secrets.
110111
publishing {
111112
token = providers.environmentVariable('JETBRAINS_MARKETPLACE_TOKEN')
112113
}
113114

114-
// signPlugin runs before publishPlugin and signs the zip with this key, and the Marketplace then adds
115-
// its own signature on top. Without the three variables signPlugin is skipped and the unsigned zip goes
116-
// up, which the Marketplace accepts as well. The values are the PEM files themselves; the private key
117-
// stays encrypted, and the password decrypts it.
118-
signing {
119-
certificateChain = providers.environmentVariable('JETBRAINS_CERTIFICATE_CHAIN')
120-
privateKey = providers.environmentVariable('JETBRAINS_PRIVATE_KEY')
121-
password = providers.environmentVariable('JETBRAINS_PRIVATE_KEY_PASSWORD')
122-
}
123-
124115
// verifyPlugin checks the plugin's bytecode against real IDEs, which it downloads. Two of them: the
125116
// IDE the plugin is built against, which is the oldest one sinceBuild admits, and the newest IntelliJ
126117
// IDEA release. The default, recommended(), would take every major version in between, which is a

0 commit comments

Comments
 (0)