From ccbfe549d3ea0959653f6080aba23ef4b093bd27 Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Mon, 31 Aug 2026 23:58:45 +0200 Subject: [PATCH 01/13] Upgrade plugin versions --- pom.xml | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/pom.xml b/pom.xml index dee20d7..4a82cea 100644 --- a/pom.xml +++ b/pom.xml @@ -41,11 +41,11 @@ 17 17 - 3.0.1 - 1.6 - 3.0.0-M1 - 1.6.8 - 3.2.1 + 3.4.0 + 3.2.8 + 3.5.6 + 1.7.0 + 3.6.2 4.2.0 @@ -66,7 +66,7 @@ 8.3.1 - 0.8.10 + 0.8.15 3.2.19.0 @@ -294,7 +294,7 @@ org.apache.maven.plugins maven-jar-plugin - 3.2.0 + 3.5.1 log4j.properties @@ -328,7 +328,7 @@ org.apache.avro avro-maven-plugin - 1.9.2 + ${avro.version} generate-sources @@ -451,7 +451,7 @@ maven-release-plugin - 2.5.3 + 3.3.1 v@{project.version} @@ -462,17 +462,17 @@ org.apache.maven.scm maven-scm-api - 1.11.2 + 2.2.1 org.apache.maven.scm maven-scm-provider-jgit - 1.11.2 + 2.2.1 org.eclipse.jgit org.eclipse.jgit - 5.5.1.201910021850-r + 7.7.1.202607240634-r @@ -487,7 +487,7 @@ org.apache.rat apache-rat-plugin - 0.13 + 0.18 validate @@ -519,7 +519,7 @@ org.spurint.maven.plugins mima-maven-plugin - 0.8.0 + 0.9.2 check-abi From 3e3ab508ce84cab305f8a7c58219da8286b2279f Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Tue, 1 Sep 2026 17:02:29 +0200 Subject: [PATCH 02/13] Add skeleton release and deploy actions --- .github/workflows/create-release.yml | 117 +++++++++++++++++++++++++++ .github/workflows/deploy.yml | 78 ++++++++++++++++++ pom.xml | 35 -------- 3 files changed, 195 insertions(+), 35 deletions(-) create mode 100644 .github/workflows/create-release.yml create mode 100644 .github/workflows/deploy.yml diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml new file mode 100644 index 0000000..f89dfc0 --- /dev/null +++ b/.github/workflows/create-release.yml @@ -0,0 +1,117 @@ +name: Create a new release + +on: + pull_request: + branches: [ master ] + + workflow_dispatch: + inputs: + tag-name: + description: 'New tag for release. Example: v0.5.2' + required: true + from-tag-name: + description: 'Previous tag to compare for release notes generation. Example: v0.5.1 Default value: latest tag.' + required: false + +jobs: + create-release: + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v4 + with: + persist-credentials: false + fetch-depth: 0 # Fetch all history for all tags and branches +# +# - uses: actions/setup-python@v6 +# with: +# python-version: '3.14' +# +# - name: Check format of received tag +# id: check-version-tag +# uses: AbsaOSS/version-tag-check@4145e48bf3f77a5afff2ec9afdd8afb6b53bce34 # v1.0.0 +# env: +# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} +# with: +# github-repository: ${{ github.repository }} +# version-tag: ${{ github.event.inputs.tag-name }} +# +# - name: Check format of received from tag +# if: ${{ github.event.inputs.from-tag-name }} +# id: check-version-from-tag +# uses: AbsaOSS/version-tag-check@4145e48bf3f77a5afff2ec9afdd8afb6b53bce34 # v1.0.0 +# env: +# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} +# with: +# github-repository: ${{ github.repository }} +# version-tag: ${{ github.event.inputs.from-tag-name }} +# should-exist: true +# +# - name: Define semantic version number +# id: semantic_version +# run: | +# TAG_NAME="${{ github.event.inputs.tag-name }}" +# VERSION=${TAG_NAME#v} +# echo "VERSION=${VERSION}" >> "${GITHUB_ENV}" +# +# - name: Configure Git +# run: | +# git config --global user.name "${{ github.actor }}" +# git config --global user.email "${{ github.actor }}@users.noreply.github.com" +# git remote set-url origin https://x-access-token:${{ secrets.GITHUB_TOKEN }}@github.com/${{ github.repository }} +# +# - name: Set up JDK +# uses: actions/setup-java@v6 +# with: +# distribution: 'temurin' +# java-version: 17 +# +# - name: Set Maven project version, create tag +# run: | +# mvn versions:set -DnewVersion=${VERSION} --no-transfer-progress +# mvn versions:commit +# git commit -am "Set project version to ${VERSION}" +# git push +# +# - name: Create tag +# run: | +# git tag ${{ github.event.inputs.tag-name }} +# git push origin ${{ github.event.inputs.tag-name }} +# +# - name: Set next development version +# run: | +# # Assumes semantic versioning and increments the minor version. Adjust the awk command as needed for different versioning schemes. +# NEXT_VERSION=$(echo ${VERSION} | awk -F. '{print $1"."$2+1".0-SNAPSHOT"}') +# mvn versions:set -DnewVersion=$NEXT_VERSION --no-transfer-progress +# mvn versions:commit +# git commit -am "Set project version to $NEXT_VERSION" +# git push +# +# - name: Generate Release Notes +# id: generate_release_notes +# uses: AbsaOSS/generate-release-notes@b4d6e3fafcff2dedc32ec751975fa3d0b3efad67 # v1.3.1 +# env: +# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} +# with: +# tag-name: ${{ github.event.inputs.tag-name }} +# from-tag-name: ${{ github.event.inputs.from-tag-name }} +# hierarchy: true +# chapters: | +# - { title: Breaking Changes 💥, labels: breaking-change } +# - { title: New Features 🎉, labels: enhancement } +# - { title: Bugfixes 🛠, labels: [bug, bugfix] } +# - { title: Other Changes, labels: [improvement, internal, chore] } +# - { title: Silent Live 🤫, catch-open-hierarchy: true} +# warnings: true +# print-empty-chapters: false +# +# - name: Create Draft Release +# uses: softprops/action-gh-release@de2c0eb89ae2a093876385947365aca7b0e5f844 # v0.1.15 +# env: +# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} +# with: +# name: ${{ github.event.inputs.tag-name }} +# body: ${{ steps.generate_release_notes.outputs.release-notes }} +# tag_name: ${{ github.event.inputs.tag-name }} +# draft: true +# prerelease: false diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml new file mode 100644 index 0000000..1454206 --- /dev/null +++ b/.github/workflows/deploy.yml @@ -0,0 +1,78 @@ +# +# Copyright 2018 ABSA Group Limited +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +name: Deploy + +on: + pull_request: + branches: [ master ] + + workflow_dispatch: + inputs: + dry-run: + description: 'If set, skips actual deployment and only performs checks.' + required: true + type: boolean + +jobs: + deploy: + runs-on: ubuntu-latest + steps: + - name: Checkout repository + uses: actions/checkout@v3 + with: + fetch-depth: 0 # Fetch all history for all tags and branches + +# - name: Check format of received tag +# id: check-version-tag +# uses: AbsaOSS/version-tag-check@4145e48bf3f77a5afff2ec9afdd8afb6b53bce34 # v1.0.0 +# env: +# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} +# with: +# github-repository: ${{ github.repository }} +# version-tag: ${{ github.ref_name }} +# should-exist: 'true' +# +# - name: Set up JDK +# uses: actions/setup-java@v6 +# with: +# distribution: 'temurin' +# java-version: 17 +# +# - name: Import GPG keys +# run: | +# echo "${{ secrets.MAVEN_GPG_PRIVATE_KEY }}" | base64 --decode | gpg --batch --import --keyserver https://keyserver.ubuntu.com/ +# echo "${{ secrets.MAVEN_GPG_PASSPHRASE }}" | gpg --passphrase-fd 0 --batch --pinentry-mode loopback --import-ownertrust <<< . +# +# +# - name: Create settings.xml +# run: | +# echo " +# +# +# ossrh +# ${{ secrets.OSSRH_USERNAME }} +# ${{ secrets.OSSRH_TOKEN }} +# +# +# " > $HOME/.m2/settings.xml +# +# - name: Build and deploy artifact +# if: ${{ !inputs.dry-run }} +# env: +# MAVEN_USERNAME: ${{ secrets.OSSRH_USERNAME }} +# MAVEN_PASSWORD: ${{ secrets.OSSRH_TOKEN }} +# run: mvn -B -e -DskipTests -Pdeploy -Dossrh clean deploy -Dossrh.username=${{ secrets.OSSRH_USERNAME }} -Dossrh.password=${{ secrets.OSSRH_TOKEN }} -Dgpg.passphrase=${{ secrets.MAVEN_GPG_PASSPHRASE }} +# \ No newline at end of file diff --git a/pom.xml b/pom.xml index 4a82cea..b9e0cb9 100644 --- a/pom.xml +++ b/pom.xml @@ -445,41 +445,6 @@ - - release - - - - maven-release-plugin - 3.3.1 - - v@{project.version} - - jgit - - - - - org.apache.maven.scm - maven-scm-api - 2.2.1 - - - org.apache.maven.scm - maven-scm-provider-jgit - 2.2.1 - - - org.eclipse.jgit - org.eclipse.jgit - 7.7.1.202607240634-r - - - - - - - license-check From b0faa4d93a6e6c5e12e1f83651862c0e90cb7bd1 Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Tue, 1 Sep 2026 17:03:55 +0200 Subject: [PATCH 03/13] Add release and deploy actions --- .github/workflows/create-release.yml | 189 +++++++++++++-------------- .github/workflows/deploy.yml | 84 ++++++------ 2 files changed, 133 insertions(+), 140 deletions(-) diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index f89dfc0..a641831 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -1,9 +1,6 @@ name: Create a new release on: - pull_request: - branches: [ master ] - workflow_dispatch: inputs: tag-name: @@ -22,96 +19,96 @@ jobs: with: persist-credentials: false fetch-depth: 0 # Fetch all history for all tags and branches -# -# - uses: actions/setup-python@v6 -# with: -# python-version: '3.14' -# -# - name: Check format of received tag -# id: check-version-tag -# uses: AbsaOSS/version-tag-check@4145e48bf3f77a5afff2ec9afdd8afb6b53bce34 # v1.0.0 -# env: -# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} -# with: -# github-repository: ${{ github.repository }} -# version-tag: ${{ github.event.inputs.tag-name }} -# -# - name: Check format of received from tag -# if: ${{ github.event.inputs.from-tag-name }} -# id: check-version-from-tag -# uses: AbsaOSS/version-tag-check@4145e48bf3f77a5afff2ec9afdd8afb6b53bce34 # v1.0.0 -# env: -# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} -# with: -# github-repository: ${{ github.repository }} -# version-tag: ${{ github.event.inputs.from-tag-name }} -# should-exist: true -# -# - name: Define semantic version number -# id: semantic_version -# run: | -# TAG_NAME="${{ github.event.inputs.tag-name }}" -# VERSION=${TAG_NAME#v} -# echo "VERSION=${VERSION}" >> "${GITHUB_ENV}" -# -# - name: Configure Git -# run: | -# git config --global user.name "${{ github.actor }}" -# git config --global user.email "${{ github.actor }}@users.noreply.github.com" -# git remote set-url origin https://x-access-token:${{ secrets.GITHUB_TOKEN }}@github.com/${{ github.repository }} -# -# - name: Set up JDK -# uses: actions/setup-java@v6 -# with: -# distribution: 'temurin' -# java-version: 17 -# -# - name: Set Maven project version, create tag -# run: | -# mvn versions:set -DnewVersion=${VERSION} --no-transfer-progress -# mvn versions:commit -# git commit -am "Set project version to ${VERSION}" -# git push -# -# - name: Create tag -# run: | -# git tag ${{ github.event.inputs.tag-name }} -# git push origin ${{ github.event.inputs.tag-name }} -# -# - name: Set next development version -# run: | -# # Assumes semantic versioning and increments the minor version. Adjust the awk command as needed for different versioning schemes. -# NEXT_VERSION=$(echo ${VERSION} | awk -F. '{print $1"."$2+1".0-SNAPSHOT"}') -# mvn versions:set -DnewVersion=$NEXT_VERSION --no-transfer-progress -# mvn versions:commit -# git commit -am "Set project version to $NEXT_VERSION" -# git push -# -# - name: Generate Release Notes -# id: generate_release_notes -# uses: AbsaOSS/generate-release-notes@b4d6e3fafcff2dedc32ec751975fa3d0b3efad67 # v1.3.1 -# env: -# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} -# with: -# tag-name: ${{ github.event.inputs.tag-name }} -# from-tag-name: ${{ github.event.inputs.from-tag-name }} -# hierarchy: true -# chapters: | -# - { title: Breaking Changes 💥, labels: breaking-change } -# - { title: New Features 🎉, labels: enhancement } -# - { title: Bugfixes 🛠, labels: [bug, bugfix] } -# - { title: Other Changes, labels: [improvement, internal, chore] } -# - { title: Silent Live 🤫, catch-open-hierarchy: true} -# warnings: true -# print-empty-chapters: false -# -# - name: Create Draft Release -# uses: softprops/action-gh-release@de2c0eb89ae2a093876385947365aca7b0e5f844 # v0.1.15 -# env: -# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} -# with: -# name: ${{ github.event.inputs.tag-name }} -# body: ${{ steps.generate_release_notes.outputs.release-notes }} -# tag_name: ${{ github.event.inputs.tag-name }} -# draft: true -# prerelease: false + + - uses: actions/setup-python@v6 + with: + python-version: '3.14' + + - name: Check format of received tag + id: check-version-tag + uses: AbsaOSS/version-tag-check@4145e48bf3f77a5afff2ec9afdd8afb6b53bce34 # v1.0.0 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + github-repository: ${{ github.repository }} + version-tag: ${{ github.event.inputs.tag-name }} + + - name: Check format of received from tag + if: ${{ github.event.inputs.from-tag-name }} + id: check-version-from-tag + uses: AbsaOSS/version-tag-check@4145e48bf3f77a5afff2ec9afdd8afb6b53bce34 # v1.0.0 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + github-repository: ${{ github.repository }} + version-tag: ${{ github.event.inputs.from-tag-name }} + should-exist: true + + - name: Define semantic version number + id: semantic_version + run: | + TAG_NAME="${{ github.event.inputs.tag-name }}" + VERSION=${TAG_NAME#v} + echo "VERSION=${VERSION}" >> "${GITHUB_ENV}" + + - name: Configure Git + run: | + git config --global user.name "${{ github.actor }}" + git config --global user.email "${{ github.actor }}@users.noreply.github.com" + git remote set-url origin https://x-access-token:${{ secrets.GITHUB_TOKEN }}@github.com/${{ github.repository }} + + - name: Set up JDK + uses: actions/setup-java@v6 + with: + distribution: 'temurin' + java-version: 17 + + - name: Set Maven project version, create tag + run: | + mvn versions:set -DnewVersion=${VERSION} --no-transfer-progress + mvn versions:commit + git commit -am "Set project version to ${VERSION}" + git push + + - name: Create tag + run: | + git tag ${{ github.event.inputs.tag-name }} + git push origin ${{ github.event.inputs.tag-name }} + + - name: Set next development version + run: | + # Assumes semantic versioning and increments the minor version. Adjust the awk command as needed for different versioning schemes. + NEXT_VERSION=$(echo ${VERSION} | awk -F. '{print $1"."$2+1".0-SNAPSHOT"}') + mvn versions:set -DnewVersion=$NEXT_VERSION --no-transfer-progress + mvn versions:commit + git commit -am "Set project version to $NEXT_VERSION" + git push + + - name: Generate Release Notes + id: generate_release_notes + uses: AbsaOSS/generate-release-notes@b4d6e3fafcff2dedc32ec751975fa3d0b3efad67 # v1.3.1 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + tag-name: ${{ github.event.inputs.tag-name }} + from-tag-name: ${{ github.event.inputs.from-tag-name }} + hierarchy: true + chapters: | + - { title: Breaking Changes 💥, labels: breaking-change } + - { title: New Features 🎉, labels: enhancement } + - { title: Bugfixes 🛠, labels: [bug, bugfix] } + - { title: Other Changes, labels: [improvement, internal, chore] } + - { title: Silent Live 🤫, catch-open-hierarchy: true} + warnings: true + print-empty-chapters: false + + - name: Create Draft Release + uses: softprops/action-gh-release@de2c0eb89ae2a093876385947365aca7b0e5f844 # v0.1.15 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + name: ${{ github.event.inputs.tag-name }} + body: ${{ steps.generate_release_notes.outputs.release-notes }} + tag_name: ${{ github.event.inputs.tag-name }} + draft: true + prerelease: false diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 1454206..2cda4bd 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -16,9 +16,6 @@ name: Deploy on: - pull_request: - branches: [ master ] - workflow_dispatch: inputs: dry-run: @@ -35,44 +32,43 @@ jobs: with: fetch-depth: 0 # Fetch all history for all tags and branches -# - name: Check format of received tag -# id: check-version-tag -# uses: AbsaOSS/version-tag-check@4145e48bf3f77a5afff2ec9afdd8afb6b53bce34 # v1.0.0 -# env: -# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} -# with: -# github-repository: ${{ github.repository }} -# version-tag: ${{ github.ref_name }} -# should-exist: 'true' -# -# - name: Set up JDK -# uses: actions/setup-java@v6 -# with: -# distribution: 'temurin' -# java-version: 17 -# -# - name: Import GPG keys -# run: | -# echo "${{ secrets.MAVEN_GPG_PRIVATE_KEY }}" | base64 --decode | gpg --batch --import --keyserver https://keyserver.ubuntu.com/ -# echo "${{ secrets.MAVEN_GPG_PASSPHRASE }}" | gpg --passphrase-fd 0 --batch --pinentry-mode loopback --import-ownertrust <<< . -# -# -# - name: Create settings.xml -# run: | -# echo " -# -# -# ossrh -# ${{ secrets.OSSRH_USERNAME }} -# ${{ secrets.OSSRH_TOKEN }} -# -# -# " > $HOME/.m2/settings.xml -# -# - name: Build and deploy artifact -# if: ${{ !inputs.dry-run }} -# env: -# MAVEN_USERNAME: ${{ secrets.OSSRH_USERNAME }} -# MAVEN_PASSWORD: ${{ secrets.OSSRH_TOKEN }} -# run: mvn -B -e -DskipTests -Pdeploy -Dossrh clean deploy -Dossrh.username=${{ secrets.OSSRH_USERNAME }} -Dossrh.password=${{ secrets.OSSRH_TOKEN }} -Dgpg.passphrase=${{ secrets.MAVEN_GPG_PASSPHRASE }} -# \ No newline at end of file + - name: Check format of received tag + id: check-version-tag + uses: AbsaOSS/version-tag-check@4145e48bf3f77a5afff2ec9afdd8afb6b53bce34 # v1.0.0 + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + with: + github-repository: ${{ github.repository }} + version-tag: ${{ github.ref_name }} + should-exist: 'true' + + - name: Set up JDK + uses: actions/setup-java@v6 + with: + distribution: 'temurin' + java-version: 17 + + - name: Import GPG keys + run: | + echo "${{ secrets.MAVEN_GPG_PRIVATE_KEY }}" | base64 --decode | gpg --batch --import --keyserver https://keyserver.ubuntu.com/ + echo "${{ secrets.MAVEN_GPG_PASSPHRASE }}" | gpg --passphrase-fd 0 --batch --pinentry-mode loopback --import-ownertrust <<< . + + + - name: Create settings.xml + run: | + echo " + + + ossrh + ${{ secrets.OSSRH_USERNAME }} + ${{ secrets.OSSRH_TOKEN }} + + + " > $HOME/.m2/settings.xml + + - name: Build and deploy artifact + if: ${{ !inputs.dry-run }} + env: + MAVEN_USERNAME: ${{ secrets.OSSRH_USERNAME }} + MAVEN_PASSWORD: ${{ secrets.OSSRH_TOKEN }} + run: mvn -B -e -DskipTests -Pdeploy -Dossrh clean deploy -Dossrh.username=${{ secrets.OSSRH_USERNAME }} -Dossrh.password=${{ secrets.OSSRH_TOKEN }} -Dgpg.passphrase=${{ secrets.MAVEN_GPG_PASSPHRASE }} From 99652fa034a2a3aab943f50c2735a8bdd87b70c6 Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Tue, 1 Sep 2026 17:06:03 +0200 Subject: [PATCH 04/13] Fix version --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index b9e0cb9..c75ff2e 100644 --- a/pom.xml +++ b/pom.xml @@ -66,7 +66,7 @@ 8.3.1 - 0.8.15 + 0.8.11 3.2.19.0 From fa472bb0e862abde5f934201ee4d5b13849ddb1b Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Wed, 2 Sep 2026 00:02:01 +0200 Subject: [PATCH 05/13] Fix release notes title --- .github/workflows/create-release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index a641831..7ac7189 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -107,7 +107,7 @@ jobs: env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: - name: ${{ github.event.inputs.tag-name }} + name: ABRiS ${{ env.VERSION}} body: ${{ steps.generate_release_notes.outputs.release-notes }} tag_name: ${{ github.event.inputs.tag-name }} draft: true From 4fc040dca8b4cf379ca0f50d17f7f4e4241a7440 Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Wed, 2 Sep 2026 00:40:50 +0200 Subject: [PATCH 06/13] Remove dry-run --- .github/workflows/deploy.yml | 16 +++++----------- 1 file changed, 5 insertions(+), 11 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 2cda4bd..707b8fe 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -17,11 +17,6 @@ name: Deploy on: workflow_dispatch: - inputs: - dry-run: - description: 'If set, skips actual deployment and only performs checks.' - required: true - type: boolean jobs: deploy: @@ -60,15 +55,14 @@ jobs: ossrh - ${{ secrets.OSSRH_USERNAME }} - ${{ secrets.OSSRH_TOKEN }} + ${{ secrets.SONATYPE_USERNAME }} + ${{ secrets.SONATYPE_PASSWORD }} " > $HOME/.m2/settings.xml - name: Build and deploy artifact - if: ${{ !inputs.dry-run }} env: - MAVEN_USERNAME: ${{ secrets.OSSRH_USERNAME }} - MAVEN_PASSWORD: ${{ secrets.OSSRH_TOKEN }} - run: mvn -B -e -DskipTests -Pdeploy -Dossrh clean deploy -Dossrh.username=${{ secrets.OSSRH_USERNAME }} -Dossrh.password=${{ secrets.OSSRH_TOKEN }} -Dgpg.passphrase=${{ secrets.MAVEN_GPG_PASSPHRASE }} + MAVEN_USERNAME: ${{ secrets.SONATYPE_USERNAME }} + MAVEN_PASSWORD: ${{ secrets.SONATYPE_PASSWORD }} + run: mvn -B -e -DskipTests -Pdeploy -Dossrh clean deploy -Dossrh.username=${{ secrets.SONATYPE_USERNAME }} -Dossrh.password=${{ secrets.SONATYPE_PASSWORD }} -Dgpg.passphrase=${{ secrets.MAVEN_GPG_PASSPHRASE }} From 8535ae8ba558556ef6d19abc67caf00d7cba645b Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Wed, 2 Sep 2026 01:20:36 +0200 Subject: [PATCH 07/13] Fix PR comments --- .github/workflows/deploy.yml | 7 +++---- pom.xml | 28 ++++++++++++---------------- 2 files changed, 15 insertions(+), 20 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 707b8fe..60359af 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -54,7 +54,7 @@ jobs: echo " - ossrh + central ${{ secrets.SONATYPE_USERNAME }} ${{ secrets.SONATYPE_PASSWORD }} @@ -63,6 +63,5 @@ jobs: - name: Build and deploy artifact env: - MAVEN_USERNAME: ${{ secrets.SONATYPE_USERNAME }} - MAVEN_PASSWORD: ${{ secrets.SONATYPE_PASSWORD }} - run: mvn -B -e -DskipTests -Pdeploy -Dossrh clean deploy -Dossrh.username=${{ secrets.SONATYPE_USERNAME }} -Dossrh.password=${{ secrets.SONATYPE_PASSWORD }} -Dgpg.passphrase=${{ secrets.MAVEN_GPG_PASSPHRASE }} + GPG_PASSPHRASE: ${{ secrets.MAVEN_GPG_PASSPHRASE }} + run: mvn -B -e -DskipTests -Pdeploy clean deploy diff --git a/pom.xml b/pom.xml index c75ff2e..8c2ca81 100644 --- a/pom.xml +++ b/pom.xml @@ -44,7 +44,7 @@ 3.4.0 3.2.8 3.5.6 - 1.7.0 + 0.11.0 3.6.2 @@ -74,17 +74,12 @@ 2.2.0 4.9.10 - - - - - ${scm.url} - ${scm.connection} - ${scm.developerConnection} - HEAD + scm:git:git://github.com/absaoss/abris.git + scm:git:ssh://github.com:absaoss/abris.git + https://github.com/AbsaOSS/ABRiS @@ -422,6 +417,7 @@ + ${env.GPG_PASSPHRASE} --pinentry-mode @@ -430,15 +426,15 @@ - org.sonatype.plugins - nexus-staging-maven-plugin - ${nexus.staging.plugin.version} + org.sonatype.central + central-publishing-maven-plugin + ${central.publishing.maven.plugin.version} true - ossrh - https://oss.sonatype.org/ - true - true + central + true + published + ${pom.groupId}:${pom.artifactId}:${project.version} From 998719ecd4ddb37452d24dca25d7e198e0df2e46 Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Wed, 2 Sep 2026 01:23:44 +0200 Subject: [PATCH 08/13] Add explicit job permissions --- .github/workflows/create-release.yml | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index 7ac7189..af806c9 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -12,6 +12,10 @@ on: jobs: create-release: + permissions: + contents: write + pull-requests: read + issues: read runs-on: ubuntu-latest steps: - name: Checkout repository From 7460aabd610fbe8b7955161461274d84965170d3 Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Wed, 2 Sep 2026 01:41:53 +0200 Subject: [PATCH 09/13] Add explicit job permissions --- .github/workflows/deploy.yml | 7 ++++++- pom.xml | 2 +- 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 60359af..dc426e8 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -20,11 +20,16 @@ on: jobs: deploy: + permissions: + contents: read + pull-requests: read + issues: read runs-on: ubuntu-latest steps: - name: Checkout repository - uses: actions/checkout@v3 + uses: actions/checkout@v4 with: + persist-credentials: false fetch-depth: 0 # Fetch all history for all tags and branches - name: Check format of received tag diff --git a/pom.xml b/pom.xml index 8c2ca81..674081c 100644 --- a/pom.xml +++ b/pom.xml @@ -77,7 +77,7 @@ - scm:git:git://github.com/absaoss/abris.git + scm:git:https://github.com/absaoss/abris.git scm:git:ssh://github.com:absaoss/abris.git https://github.com/AbsaOSS/ABRiS From 8237027583186fc5ef04c554992d61a910050c74 Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Wed, 2 Sep 2026 09:56:40 +0200 Subject: [PATCH 10/13] Update secret names --- .github/workflows/deploy.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index dc426e8..1c592a4 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -50,8 +50,8 @@ jobs: - name: Import GPG keys run: | - echo "${{ secrets.MAVEN_GPG_PRIVATE_KEY }}" | base64 --decode | gpg --batch --import --keyserver https://keyserver.ubuntu.com/ - echo "${{ secrets.MAVEN_GPG_PASSPHRASE }}" | gpg --passphrase-fd 0 --batch --pinentry-mode loopback --import-ownertrust <<< . + echo "${{ secrets.PGP_SECRET }}" | base64 --decode | gpg --batch --import --keyserver https://keyserver.ubuntu.com/ + echo "${{ secrets.PGP_PASSPHRASE }}" | gpg --passphrase-fd 0 --batch --pinentry-mode loopback --import-ownertrust <<< . - name: Create settings.xml @@ -68,5 +68,5 @@ jobs: - name: Build and deploy artifact env: - GPG_PASSPHRASE: ${{ secrets.MAVEN_GPG_PASSPHRASE }} + GPG_PASSPHRASE: ${{ secrets.PGP_PASSPHRASE }} run: mvn -B -e -DskipTests -Pdeploy clean deploy From df5bca1de3b19b3e0440d55c5556674ce950132f Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Wed, 2 Sep 2026 12:57:27 +0200 Subject: [PATCH 11/13] Fix actions --- .github/workflows/create-release.yml | 1 + .github/workflows/deploy.yml | 11 ++++++++--- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index af806c9..6764097 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -17,6 +17,7 @@ jobs: pull-requests: read issues: read runs-on: ubuntu-latest + environment: release steps: - name: Checkout repository uses: actions/checkout@v4 diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 1c592a4..0704390 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -25,7 +25,14 @@ jobs: pull-requests: read issues: read runs-on: ubuntu-latest + environment: release steps: + - name: Validate ref is a tag + if: github.ref_type != 'tag' + run: | + echo "This workflow must run from a tag." + exit 1 + - name: Checkout repository uses: actions/checkout@v4 with: @@ -50,9 +57,7 @@ jobs: - name: Import GPG keys run: | - echo "${{ secrets.PGP_SECRET }}" | base64 --decode | gpg --batch --import --keyserver https://keyserver.ubuntu.com/ - echo "${{ secrets.PGP_PASSPHRASE }}" | gpg --passphrase-fd 0 --batch --pinentry-mode loopback --import-ownertrust <<< . - + echo "${{ secrets.PGP_SECRET }}" | base64 --decode | gpg --batch --import - name: Create settings.xml run: | From 320f74c8f5858bdb0c0b87ed08600b35c64b2c22 Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Wed, 2 Sep 2026 12:58:57 +0200 Subject: [PATCH 12/13] skip actual deploy for testing --- .github/workflows/deploy.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 0704390..5dfb9f8 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -72,6 +72,7 @@ jobs: " > $HOME/.m2/settings.xml - name: Build and deploy artifact + if: false env: GPG_PASSPHRASE: ${{ secrets.PGP_PASSPHRASE }} run: mvn -B -e -DskipTests -Pdeploy clean deploy From 614d13eba5057683452e011b0e1a45288948d148 Mon Sep 17 00:00:00 2001 From: Kevin Wallimann Date: Wed, 2 Sep 2026 13:08:55 +0200 Subject: [PATCH 13/13] Rename environmnet, activate deploy workflow --- .github/workflows/create-release.yml | 2 +- .github/workflows/deploy.yml | 3 +-- 2 files changed, 2 insertions(+), 3 deletions(-) diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index 6764097..647fb80 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -17,7 +17,7 @@ jobs: pull-requests: read issues: read runs-on: ubuntu-latest - environment: release + environment: publish steps: - name: Checkout repository uses: actions/checkout@v4 diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index 5dfb9f8..062d6a0 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -25,7 +25,7 @@ jobs: pull-requests: read issues: read runs-on: ubuntu-latest - environment: release + environment: publish steps: - name: Validate ref is a tag if: github.ref_type != 'tag' @@ -72,7 +72,6 @@ jobs: " > $HOME/.m2/settings.xml - name: Build and deploy artifact - if: false env: GPG_PASSPHRASE: ${{ secrets.PGP_PASSPHRASE }} run: mvn -B -e -DskipTests -Pdeploy clean deploy