Skip to content

Fix Maven Central signing and bump version to 2.4.0 - #141

Merged
robgordon89 merged 2 commits into
mainfrom
fix/maven-gpg-signing
Sep 29, 2026
Merged

robgordon89 merged 2 commits into
mainfrom
fix/maven-gpg-signing

Conversation

@robgordon89

Copy link
Copy Markdown
Contributor

Why?

Releases 2.2.0, 2.3.0 and 2.4.0 all failed at gpg:sign, so Maven Central still stops at 2.1.0. There were two causes: the signing key had expired (renewed separately, and MAVEN_GPG_PRIVATE_KEY updated), and setup-java v6 (#135) no longer writes the gpg.passphrase server entry into settings.xml, which is the only place maven-gpg-plugin 1.6 reads the passphrase from. The v2.4.0 tag was also cut with the pom still at 2.3.0.

Changes

  1. pom.xml: maven-gpg-plugin 1.6 → 3.2.8. 3.2.x reads the passphrase from the MAVEN_GPG_PASSPHRASE env var (its default passphraseEnvName), which publish.yaml already sets for the mvn step. This is what setup-java v6 expects. It also passes --batch --pinentry-mode loopback itself.
  2. pom.xml, README.md: version 2.3.0 → 2.4.0, in the same places as previous bumps.

Risks

  • This PR's Build workflow doesn't exercise signing (mvn test stops before verify), and it wasn't run locally because the devshell has no JDK or Maven. The first real run is the release. If it fails there, it fails before deploy, so nothing is published.
  • Maven Central versions are immutable. Don't re-run the existing v2.4.0 publish run (36012690818). Its tag's pom says 2.3.0, so a successful attempt would publish 2.4.0 code as java-sdk:2.3.0.
  • The existing gpgArguments (--pinentry-mode loopback) now repeat a flag 3.2.8 passes itself. Checked locally with gpg 2.4.9: signing with the flag repeated and the passphrase on stdin works.

Performance impact

None. Build-time plugin only; the SDK code is unchanged.

Security impact

No security impact. The passphrase still comes from the MAVEN_GPG_PASSPHRASE secret via the step env; the plugin now reads it from the environment instead of through settings.xml.

How to QA

No SDK code changed, so there is nothing to QA in the library itself. The check is the publish run after merge:

  1. In the Maven Publish log, gpg:sign (sign-artifacts) passes.
  2. 2.4.0 appears in https://repo1.maven.org/maven2/com/mailersend/java-sdk/maven-metadata.xml.

How to release

  1. Merge.
  2. Publish 2.4.0 from the merge commit: either recreate the v2.4.0 release/tag on it, or run Maven Publish manually (workflow_dispatch) on main.
  3. 2.2.0 and 2.3.0 were never published; 2.4.0 includes their changes.

Rollback strategy

  • Migrations: none.
  • Data changes: none.
  • External dependencies: maven-gpg-plugin is build-time only. Reverting to 1.6 on its own won't sign under setup-java v6; the fallback is pinning setup-java back to v5 in publish.yaml.
  • Config: none.
  • A version published to Maven Central can't be pulled. A bad 2.4.0 would be superseded by 2.4.1.

Screenshots, recordings

N/A

I used AI to generate parts of this PR

Yes

🤖 Generated with Claude Code

robgordon89 and others added 2 commits September 29, 2026 17:24
setup-java v6 no longer writes the gpg.passphrase server into
settings.xml; it expects the plugin to read MAVEN_GPG_PASSPHRASE from
the environment. Plugin 1.6 only reads the settings.xml server, so gpg
got no passphrase and failed with "no terminal at all requested".
3.2.x reads MAVEN_GPG_PASSPHRASE, which publish.yaml already sets.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The v2.4.0 tag was cut with the pom still at 2.3.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@robgordon89 robgordon89 self-assigned this Sep 29, 2026
@robgordon89
robgordon89 marked this pull request as ready for review September 29, 2026 16:29
@robgordon89
robgordon89 merged commit 2048ec8 into main Sep 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant