Skip to content

Initial release pipeline - #161

Merged
arunav-gandhi merged 1 commit into
masterfrom
feature/release
Oct 8, 2026
Merged

arunav-gandhi merged 1 commit into
masterfrom
feature/release

Conversation

@arunav-gandhi

@arunav-gandhi arunav-gandhi commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Description

Introduces a complete GitHub Actions release pipeline for the Guardian Android SDK following the existing 3-layer build contract (GHA → build.sh → Fastlane → Gradle).

Changes:

  • .github/workflows/release.yml — New workflow_dispatch-only release workflow with 3 jobs:
    • validate-version — asserts the branch matches release/X.Y.Z, auto-syncs .version to the branch name, outputs the final SHA so all jobs pin to the same commit
    • test — runs the full unit test suite against the pinned commit
    • publish — gated by the maven-central-release GitHub environment (human approval gate). On approval: validates idempotency, uploads to Maven Central staging via ./build.sh --publish, auto-generates and commits CHANGELOG.md, creates an annotated git tag, creates a GitHub Release with auto-generated notes, and opens a PR back to master
  • tools/build/args.sh — Added --publish / --nopublish flags; resolve_plan() appends the publish_maven Fastlane lane when set
  • fastlane/Fastfile — Added publish_maven lane guarded by RELEASE_CONTEXT=true — hard-errors if called outside the release pipeline, preventing accidental local publishes

Security hardening: set -euo pipefail on all shell blocks, preflight idempotency guard before Maven upload, secrets scoped to environment (not repo-wide), quoted heredoc for credential injection, random GITHUB_ENV delimiter against PR-title injection, SHA pinning across jobs.

References

https://auth0team.atlassian.net/browse/NAPP-125

Testing

  • Regex validated locally against edge cases: release/1.2 ❌, release/1.2.3-test ❌, release/1.2.3sdhasda ❌, release/1.2.3 ✅

  • 3-agent parallel security/shell/trigger cross-review + adversarial re-verification pass — all 10 findings addressed and confirmed fixed

  • RELEASE_CONTEXT guard confirmed: running ./build.sh --publish locally without the env var aborts immediately with a clear error message

  • set -euo pipefail verified: empty API responses, missing .version, and rejected git pushes all produce hard failures before any irreversible work is done

  • This change adds test coverage for new/changed/fixed functionality

Checklist

  • I have added documentation for new/changed functionality in this PR or in auth0.com/docs
  • All active GitHub checks for tests, formatting, and security are passing
  • The correct base branch is being used, if not the default branch

Co-Authored-By: Claude <noreply@anthropic.com>
@arunav-gandhi arunav-gandhi changed the title Feature/release Initial release pipeline Oct 8, 2026
@arunav-gandhi
arunav-gandhi merged commit d72e349 into master Oct 8, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants