Skip to content

chore: migrate publishing to Maven Central and harden GitHub Actions - #151

Open
kridai wants to merge 1 commit into
mainfrom
chore/central-publishing-and-ci-hardening
Open

kridai wants to merge 1 commit into
mainfrom
chore/central-publishing-and-ci-hardening

Conversation

@kridai

@kridai kridai commented Oct 5, 2026

Copy link
Copy Markdown

Summary

Gets java-http-client releasable again and in line with the platform team's GitHub Actions requirements. This is a prerequisite for the HttpClient 5 upgrade (DII-2524). It mirrors sendgrid/sendgrid-java#785 and the Central migration in sendgrid/sendgrid-java#777 / #778.

Release process (OSSRH → Maven Central Portal)

OSSRH (oss.sonatype.org) has been shut down, so the current release path can't publish.

  • nexus-staging-maven-plugin 1.6.8 replaced with central-publishing-maven-plugin 0.8.0 (publishingServerId: central, autoPublish: true). This is the same config sendgrid-java and twilio-java use.
  • Deploy job server-id: ossrh changed to central.
  • Removed the deprecated org.sonatype.oss:oss-parent parent POM, as sendgrid-java did.
  • Added a <developers> block. Central Portal rejects bundles without one, and this POM never had it. I reused twilio-java's org-level entry (Twilio API <api@twilio.com>), so please confirm that's the right contact for a SendGrid library.

SONATYPE_USERNAME / SONATYPE_PASSWORD must be Central Portal user tokens, not the old OSSRH credentials. If this repo's secrets weren't rotated with sendgrid-java's, they need to be before the first release.

GitHub Actions hardening

  • All actions pinned to commit SHAs, with Dependabot (github-actions) keeping them current.
  • Per-job permissions, ubuntu-x64 runners, and a repository_owner == 'sendgrid' guard.
  • PR title lint now uses twilio/sdk-actions/semantic-pr-title. GitHub Release now uses twilio/sdk-actions/github-release, with fetch-depth: 0, changelog-file: CHANGELOG.md, and the footer's ${version} replaced by ${{ github.ref_name }}.
  • Slack notifications and the Datadog metric are commented out (not on the allowlist).
  • Removed update-dependencies.yml (PAT plus a direct push to main) in favour of Dependabot maven.

Other

  • LICENSE year updated to 2026. LicenseTest asserts the current year, so it was failing on main.

Testing (in maven:3.9-eclipse-temurin-8, matching the deploy JDK)

  • mvn test: 18 tests, 0 failures.
  • mvn clean package -Prelease -Dgpg.skip: the Central plugin resolves, and the jar, -sources.jar and -javadoc.jar are all produced.
  • actionlint: clean apart from the expected unknown-label warning for the self-hosted ubuntu-x64.
  • An actual Central upload can only be checked on the next tag.

🤖 Generated with Claude Code

- Replace nexus-staging-maven-plugin (OSSRH, shut down) with central-publishing-maven-plugin 0.8.0
- Drop the deprecated org.sonatype.oss:oss-parent parent POM
- Add the <developers> block required by Central Portal validation
- Pin all actions to commit SHAs, add per-job permissions, run on ubuntu-x64
- Use twilio/sdk-actions semantic-pr-title and github-release
- Comment out Slack notifications and the Datadog release metric
- Replace update-dependencies workflow with Dependabot (maven + github-actions)
- Update LICENSE year so LicenseTest passes

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant