From 8ad2476c0cb70af7b352ebf076c0f1e18e10ed41 Mon Sep 17 00:00:00 2001 From: Mattt Date: Wed, 16 Sep 2026 09:42:08 +0100 Subject: [PATCH 1/3] fix(release): use current Central Portal for package publishing --- .github/workflows/release.yml | 2 +- CHANGELOG.md | 6 ++++++ build.gradle | 5 +++-- lib/build.gradle | 2 +- package.json | 2 +- 5 files changed, 12 insertions(+), 5 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index fc7c21a..4c4774d 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -71,7 +71,7 @@ jobs: ' CHANGELOG.md) gh release create $COMMIT_TAG -t "$COMMIT_TAG" -n "$CHANGELOG" ./generate_gradle_properties.bash ${{ github.workspace }} - ./gradlew publishToSonatype closeAndReleaseSonatypeStagingRepository + ./gradlew publishToSonatype closeSonatypeStagingRepository else echo "No tag attached to HEAD. No new release needed." fi \ No newline at end of file diff --git a/CHANGELOG.md b/CHANGELOG.md index 1bcfded..5b3d007 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # evervault-java +## 4.3.1 + +### Patch Changes + +- Update release process from deprecated OSSRH to Maven Central Portal. + ## 4.3.0 ### Minor Changes diff --git a/build.gradle b/build.gradle index fd4b6df..07bef88 100644 --- a/build.gradle +++ b/build.gradle @@ -25,8 +25,9 @@ def getRepositoryPassword() { nexusPublishing { repositories { sonatype { - nexusUrl.set(uri("https://s01.oss.sonatype.org/service/local/")) - snapshotRepositoryUrl.set(uri("https://s01.oss.sonatype.org/content/repositories/snapshots/")) + nexusUrl.set(uri("https://ossrh-staging-api.central.sonatype.com/service/local/")) + snapshotRepositoryUrl.set(uri("https://central.sonatype.com/repository/maven-snapshots/")) + stagingProfileId.set("7050c947df3733") username = getRepositoryUsername() password = getRepositoryPassword() } diff --git a/lib/build.gradle b/lib/build.gradle index 680977b..9ac0016 100644 --- a/lib/build.gradle +++ b/lib/build.gradle @@ -6,7 +6,7 @@ plugins { } group 'com.evervault' -version '4.3.0' +version '4.3.1' repositories { mavenCentral() diff --git a/package.json b/package.json index 2bf20c8..489d42c 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "evervault-java", "private": true, - "version": "4.3.0", + "version": "4.3.1", "scripts": { "version": "changeset version && PACKAGE_VERSION=$(node -p \"require('./package.json').version\") && sed -i \"s/version '.*'/version '$PACKAGE_VERSION'/g\" lib/build.gradle" }, From 90b6b8e93bab5b812f470ede7f62998053900266 Mon Sep 17 00:00:00 2001 From: Mattt Date: Wed, 16 Sep 2026 11:15:57 +0100 Subject: [PATCH 2/3] fix(release): split staging and release into two jobs, with approval on release --- .github/workflows/release.yml | 89 ++++++++++++++++++++++++++--------- 1 file changed, 68 insertions(+), 21 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 4c4774d..6d9b0ae 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -6,9 +6,19 @@ on: - master - main +concurrency: + group: release + cancel-in-progress: false + +permissions: + contents: write + pull-requests: write + jobs: - changesets: + stage: runs-on: ubuntu-latest + outputs: + tag: ${{ steps.release.outputs.tag }} env: SONATYPE_USERNAME: ${{ secrets.SONATYPE_USERNAME }} SONATYPE_PASSWORD: ${{ secrets.SONATYPE_PASSWORD }} @@ -50,28 +60,65 @@ jobs: version-script: npm run version github-token: ${{ secrets.GITHUB_TOKEN }} - - name: Create new release if release PR is merged + - name: Tag and create GitHub release if release PR is merged + id: release if: steps.changesets.outputs.has-changesets == 'false' + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | npx changeset git-tag && git push origin --tags COMMIT_TAG=$(git tag --points-at HEAD) - if [ -n "$COMMIT_TAG" ]; then - echo "A tag is attached to HEAD. Creating a new release..." - echo "${{ secrets.GITHUB_TOKEN }}" | gh auth login --with-token - CHANGELOG=$(awk ' - BEGIN { recording=0; } - /^## / { - if(recording) { exit; } - recording=1; - next; - } - recording { - print; - } - ' CHANGELOG.md) - gh release create $COMMIT_TAG -t "$COMMIT_TAG" -n "$CHANGELOG" - ./generate_gradle_properties.bash ${{ github.workspace }} - ./gradlew publishToSonatype closeSonatypeStagingRepository - else + if [ -z "$COMMIT_TAG" ]; then echo "No tag attached to HEAD. No new release needed." - fi \ No newline at end of file + exit 0 + fi + echo "A tag is attached to HEAD. Creating a new release..." + CHANGELOG=$(awk ' + BEGIN { recording=0; } + /^## / { + if(recording) { exit; } + recording=1; + next; + } + recording { + print; + } + ' CHANGELOG.md) + gh release create "$COMMIT_TAG" -t "$COMMIT_TAG" -n "$CHANGELOG" + echo "tag=$COMMIT_TAG" >> "$GITHUB_OUTPUT" + + - name: Stage ${{ steps.release.outputs.tag }} to Sonatype + if: steps.release.outputs.tag != '' + run: | + ./generate_gradle_properties.bash ${{ github.workspace }} + ./gradlew publishToSonatype closeSonatypeStagingRepository + + publish: + needs: stage + if: needs.stage.outputs.tag != '' + runs-on: ubuntu-latest + environment: + name: maven-central + url: https://central.sonatype.com/publishing/deployments + env: + SONATYPE_USERNAME: ${{ secrets.SONATYPE_USERNAME }} + SONATYPE_PASSWORD: ${{ secrets.SONATYPE_PASSWORD }} + GPG_KEY_FILE: ${{ secrets.GPG_KEY_FILE }} + GPG_KEY_PASSWORD: ${{ secrets.GPG_KEY_PASSWORD }} + GPG_KEY_ID: ${{ secrets.GPG_KEY_ID }} + steps: + - name: Checkout release tag + uses: actions/checkout@v7 + with: + ref: ${{ needs.stage.outputs.tag }} + + - name: Setup java environment + uses: actions/setup-java@v6 + with: + distribution: 'corretto' + java-version: '17' + + - name: Release ${{ needs.stage.outputs.tag }} to Maven Central + run: | + ./generate_gradle_properties.bash ${{ github.workspace }} + ./gradlew findSonatypeStagingRepository releaseSonatypeStagingRepository From 9009500d8c9190b1527fcc3d2fd216274822f4aa Mon Sep 17 00:00:00 2001 From: Mattt Date: Wed, 16 Sep 2026 11:18:45 +0100 Subject: [PATCH 3/3] fix(release): add version to gradle properties to tag staging package --- build.gradle | 1 + 1 file changed, 1 insertion(+) diff --git a/build.gradle b/build.gradle index 07bef88..c27169a 100644 --- a/build.gradle +++ b/build.gradle @@ -9,6 +9,7 @@ plugins { } group 'com.evervault' +version new groovy.json.JsonSlurper().parseText(file('package.json').text).version dependencyLocking { lockAllConfigurations()