Repository navigation
Publish #10
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish | |
| # Default permissions are least-privilege; the publish job elevates to | |
| # contents: write / packages: write below. This satisfies zizmor's | |
| # excessive-permissions check. | |
| permissions: | |
| contents: read | |
| on: | |
| push: | |
| tags: ['v*'] | |
| workflow_dispatch: | |
| jobs: | |
| test: | |
| name: Build & Test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Set up JDK 17 | |
| uses: actions/setup-java@v5 | |
| with: | |
| distribution: 'temurin' | |
| java-version: '17' | |
| - name: Run tests | |
| run: gradle --no-daemon test | |
| - name: Upload test results | |
| if: always() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: test-results | |
| path: build/reports/tests/test/ | |
| publish: | |
| name: Publish | |
| runs-on: ubuntu-latest | |
| # Tag pushes can't depend on the separate Test workflow, so tests are | |
| # re-run here and the publish job is gated on them succeeding. | |
| needs: test | |
| permissions: | |
| contents: write | |
| packages: write | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Set up JDK 17 | |
| uses: actions/setup-java@v5 | |
| with: | |
| distribution: 'temurin' | |
| java-version: '17' | |
| - name: Publish to GitHub Packages | |
| run: gradle --no-daemon publishMavenPublicationToGitHubPackagesRepository | |
| env: | |
| GITHUB_USER: ${{ github.actor }} | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Publish to Maven Central | |
| # Uploads via the Central Portal publisher API (com.gradleup.nmcp) | |
| # and auto-releases after validation, so artifacts sync to Maven | |
| # Central. The legacy OSSRH staging API shim stopped accepting | |
| # deployments in 2026. | |
| run: gradle --no-daemon publishAggregationToCentralPortal | |
| env: | |
| SONATYPE_USERNAME: ${{ secrets.SONATYPE_USERNAME }} | |
| SONATYPE_PASSWORD: ${{ secrets.SONATYPE_PASSWORD }} | |
| SIGNING_KEY: ${{ secrets.GPG_PRIVATE_KEY }} | |
| SIGNING_PASSWORD: ${{ secrets.GPG_PASSPHRASE }} |