Conversation
- Replace nexus-staging-maven-plugin (OSSRH, shut down) with central-publishing-maven-plugin 0.8.0 - Drop the deprecated org.sonatype.oss:oss-parent parent POM - Add the <developers> block required by Central Portal validation - Pin all actions to commit SHAs, add per-job permissions, run on ubuntu-x64 - Use twilio/sdk-actions semantic-pr-title and github-release - Comment out Slack notifications and the Datadog release metric - Replace update-dependencies workflow with Dependabot (maven + github-actions) - Update LICENSE year so LicenseTest passes Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Gets java-http-client releasable again and in line with the platform team's GitHub Actions requirements. This is a prerequisite for the HttpClient 5 upgrade (DII-2524). It mirrors sendgrid/sendgrid-java#785 and the Central migration in sendgrid/sendgrid-java#777 / #778.
Release process (OSSRH → Maven Central Portal)
OSSRH (
oss.sonatype.org) has been shut down, so the current release path can't publish.nexus-staging-maven-plugin1.6.8 replaced withcentral-publishing-maven-plugin0.8.0 (publishingServerId: central,autoPublish: true). This is the same config sendgrid-java and twilio-java use.server-id: ossrhchanged tocentral.org.sonatype.oss:oss-parentparent POM, as sendgrid-java did.<developers>block. Central Portal rejects bundles without one, and this POM never had it. I reused twilio-java's org-level entry (Twilio API <api@twilio.com>), so please confirm that's the right contact for a SendGrid library.SONATYPE_USERNAME/SONATYPE_PASSWORDmust be Central Portal user tokens, not the old OSSRH credentials. If this repo's secrets weren't rotated with sendgrid-java's, they need to be before the first release.GitHub Actions hardening
github-actions) keeping them current.permissions,ubuntu-x64runners, and arepository_owner == 'sendgrid'guard.twilio/sdk-actions/semantic-pr-title. GitHub Release now usestwilio/sdk-actions/github-release, withfetch-depth: 0,changelog-file: CHANGELOG.md, and the footer's${version}replaced by${{ github.ref_name }}.update-dependencies.yml(PAT plus a direct push tomain) in favour of Dependabotmaven.Other
LICENSEyear updated to 2026.LicenseTestasserts the current year, so it was failing onmain.Testing (in
maven:3.9-eclipse-temurin-8, matching the deploy JDK)mvn test: 18 tests, 0 failures.mvn clean package -Prelease -Dgpg.skip: the Central plugin resolves, and the jar,-sources.jarand-javadoc.jarare all produced.actionlint: clean apart from the expected unknown-label warning for the self-hostedubuntu-x64.🤖 Generated with Claude Code