Repository navigation
Fix Maven Central signing and bump version to 2.4.0 - #141
Merged
Merged
Conversation
setup-java v6 no longer writes the gpg.passphrase server into settings.xml; it expects the plugin to read MAVEN_GPG_PASSPHRASE from the environment. Plugin 1.6 only reads the settings.xml server, so gpg got no passphrase and failed with "no terminal at all requested". 3.2.x reads MAVEN_GPG_PASSPHRASE, which publish.yaml already sets. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The v2.4.0 tag was cut with the pom still at 2.3.0. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why?
Releases 2.2.0, 2.3.0 and 2.4.0 all failed at
gpg:sign, so Maven Central still stops at 2.1.0. There were two causes: the signing key had expired (renewed separately, andMAVEN_GPG_PRIVATE_KEYupdated), and setup-java v6 (#135) no longer writes thegpg.passphraseserver entry intosettings.xml, which is the only place maven-gpg-plugin 1.6 reads the passphrase from. The v2.4.0 tag was also cut with the pom still at 2.3.0.Changes
pom.xml: maven-gpg-plugin 1.6 → 3.2.8. 3.2.x reads the passphrase from theMAVEN_GPG_PASSPHRASEenv var (its defaultpassphraseEnvName), whichpublish.yamlalready sets for themvnstep. This is what setup-java v6 expects. It also passes--batch --pinentry-mode loopbackitself.pom.xml,README.md: version 2.3.0 → 2.4.0, in the same places as previous bumps.Risks
mvn teststops beforeverify), and it wasn't run locally because the devshell has no JDK or Maven. The first real run is the release. If it fails there, it fails before deploy, so nothing is published.java-sdk:2.3.0.gpgArguments(--pinentry-mode loopback) now repeat a flag 3.2.8 passes itself. Checked locally with gpg 2.4.9: signing with the flag repeated and the passphrase on stdin works.Performance impact
None. Build-time plugin only; the SDK code is unchanged.
Security impact
No security impact. The passphrase still comes from the
MAVEN_GPG_PASSPHRASEsecret via the step env; the plugin now reads it from the environment instead of throughsettings.xml.How to QA
No SDK code changed, so there is nothing to QA in the library itself. The check is the publish run after merge:
gpg:sign (sign-artifacts)passes.2.4.0appears in https://repo1.maven.org/maven2/com/mailersend/java-sdk/maven-metadata.xml.How to release
workflow_dispatch) onmain.Rollback strategy
publish.yaml.Screenshots, recordings
N/A
I used AI to generate parts of this PR
Yes
🤖 Generated with Claude Code