feat(publish): migrate canonical-cbor + tx-codec to Sonatype Central Portal - #16
Merged
Merged
Conversation
The existing release.yml already auto-publishes :sdk-protobuf and
:wallet-sdk on tag push, but the two new subprojects this PR
introduces sit outside the root build (their own settings.gradle,
because the root still references the shut-down jcenter() repo). So
without this change every release of canonical-cbor / tx-codec would
need a manual `cd canonical-cbor && gradle publish` step.
Changes:
- Makefile: split `maven` into `maven-legacy` (existing root-build
modules) and `maven-cbor` (standalone subprojects). Same split for
`mavenLocal`. Comment records why the split exists and notes when
it can fold back together (root build modernisation).
- .github/workflows/release.yml:
* setup-java 1.8 -> 17 (Gradle 7.2 root wrapper supports Java
11+, canonical-cbor / tx-codec require jvmToolchain(17)).
* Add gradle/actions/setup-gradle@v3 pinned to 9.1.0 so the
`gradle clean publish` invocations inside maven-cbor have a
modern system Gradle to drive the standalone subprojects.
Root `./gradlew` calls are unaffected — they still resolve to
Gradle 7.2 via the wrapper.
* Forward NEXUS_USERNAME / NEXUS_PASSWORD secrets so the
Sonatype publishing config (s01.oss.sonatype.org/staging) can
authenticate. Same secret names the existing wallet-sdk
publish already uses via gradle.properties.
Verified locally: `make mavenLocal-cbor` produces the expected
artifacts under ~/.m2/repository/io/arcblock/did/sdk-{canonical-cbor,
tx-codec}/<version>/ with .jar / -sources.jar / -javadoc.jar / .pom.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Code Coverage
|
…Portal
Legacy OSSRH (s01.oss.sonatype.org) was sunset 2025-06-30 and no longer
accepts new uploads. Replace the partial publishing config (which had
no `repositories` block at all and would have silently no-op'd on
`gradle publish`) with the vanniktech maven-publish plugin pinned to
the `CENTRAL_PORTAL` host.
Plugin gives us, out of the box:
- Central Portal API endpoint + staging deployment workflow
- sources jar + javadoc jar attached to the publication
- signing applied to all 5 artifacts (jar / sources / javadoc / pom /
module) — confirmed with `gpg --verify` against a freshly-generated
RSA 4096 key (fingerprint 2658 7907 86AD E23D D0A2 D02A 263E 368E
341C E76C, public key on keys.openpgp.org)
- `publishAndReleaseToMavenCentral` one-shot task that uploads to
staging and auto-releases once Central's validation passes — no
manual "Close → Release" click in the Portal UI
POM is now Central-Portal-validation-complete on both modules: name,
description, url, inceptionYear, license (with distribution), developer
(with id/name/email/url), scm (connection / developerConnection / url).
The previous tx-codec pom was missing developer + scm — would have been
rejected by Central's verification step.
Signing uses `signing.useGpgCmd()` so the publisher's private key stays
in their local GnuPG keyring (modern GnuPG 2.5 keyboxd backend), no
secring.gpg or in-memory armored key in gradle.properties. pinentry-mac
prompts for the passphrase on first sign per session and gpg-agent
caches it for subsequent artifacts in the same publish run.
Required `~/.gradle/gradle.properties` on the publishing machine:
mavenCentralUsername=<central-portal-user-token-name>
mavenCentralPassword=<central-portal-user-token-secret>
signing.gnupg.keyName=<last-8-hex-of-publisher-gpg-long-key-id>
Smoke-tested locally on both modules with `gradle clean
publishToMavenLocal`: 5 artifacts + 5 .asc per module, every signature
verifies "Good signature" against the publisher's public key.
The legacy `protobuf` and `wallet-sdk` modules are intentionally
untouched — neither has any source change since their last respective
publish (sdk-protobuf 1.0.19 on 2025-10-11, wallet-sdk 1.0.14 on
2025-01-21), so the 1.0.15 release ships only the two new modules.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Code Coverage
|
First publish of canonical-cbor + tx-codec via the new Sonatype Central Portal flow (paper's legacy OSSRH credentials retired with his account; io.arcblock.did namespace ownership migrated to the org account, new publisher is Pengfei via Central Portal user token). sdk-protobuf stays at 1.0.19 and wallet-sdk stays at 1.0.14 — neither has any source change since their last publish, so they're not part of this release. The wallet-side `arc-wallet-android/config.gradle` will bump only its sdk-canonical-cbor + sdk-tx-codec coordinates, leaving walletSdkVersion / sdk-protobuf pins untouched. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Code Coverage
|
3 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Background
Legacy OSSRH (
s01.oss.sonatype.org) was sunset by Sonatype on 2025-06-30 and no longer accepts new uploads. The previouscanonical-cbor/tx-codecpublishingconfig had:publications {}block with the artifact metadatarepositories {}block at all —gradle publishwould have silently no-op'd, never reaching Sonatypesigning {}block — Maven Central rejects unsigned artifactsThis PR closes those gaps end-to-end.
What this PR does
canonical-cbor/build.gradle+tx-codec/build.gradle: replace hand-rolledpublishingblocks withcom.vanniktech.maven.publish:0.30.0, the de-facto plugin for OSS Android library publishing. Configure withhost = "CENTRAL_PORTAL"andautomaticRelease = trueso a singlepublishAndReleaseToMavenCentraltask uploads + auto-releases once Central's validation passes.name,description,url,inceptionYear,license(withdistribution),developer(withid/name/email/url),scm(withconnection/developerConnection/url). The previous tx-codec pom was missingdeveloper+scmand would have been rejected.signing.useGpgCmd()so the publisher's private key stays in their local GnuPG keyring (modern GnuPG 2.5 keyboxd backend). No secring.gpg, no in-memory armored key in gradle.properties.Makefile:maven-cbortarget now invokespublishAndReleaseToMavenCentralinstead of plainpublish.Modules NOT touched (intentional)
protobuf(sdk-protobuf) andwallet-sdkare untouched — neither has any source change since their last respective publish (sdk-protobuf 1.0.19 on 2025-10-11, wallet-sdk 1.0.14 on 2025-01-21). The 1.0.15 release ships only the two new modules. Migrating those legacy modules to the Central Portal can be done later when a real version bump is needed.Required publisher setup
Configured in
~/.gradle/gradle.properties(NOT committed to the repo):The publisher must also have a GPG signing key with public half pushed to
keys.openpgp.organd the email address verified on that keyserver, so Sonatype's signature validation can resolve the public key.Verification
Smoke-tested locally on both modules:
→ 5 artifacts + 5
.ascsignatures per module:Every
.ascverifiesGood signatureagainst the publisher's public key.Test plan
cd canonical-cbor && gradle clean publishToMavenLocaland confirms 5 artifacts + 5 .asc generatedtx-codecversionto 1.0.15, runmake maven-cbor, confirm both artifacts appear on Maven Central within ~30 min🤖 Generated with Claude Code