|
5 | 5 | types: [created] |
6 | 6 |
|
7 | 7 | jobs: |
8 | | - publish: |
| 8 | + build: |
9 | 9 | runs-on: ubuntu-latest |
10 | 10 |
|
11 | 11 | steps: |
12 | | - - name: Checkout source code |
13 | | - uses: actions/checkout@v4 |
14 | | - |
15 | | - - name: Set up Java |
16 | | - uses: actions/setup-java@v4 |
17 | | - with: |
18 | | - distribution: 'temurin' |
19 | | - java-version: '17' |
20 | | - server-id: central |
21 | | - server-username: MAVEN_CENTRAL_USERNAME |
22 | | - server-password: MAVEN_CENTRAL_TOKEN |
23 | | - java-package: jdk |
24 | | - check-latest: false |
25 | | - overwrite-settings: true |
26 | | - |
27 | | - - name: Clean GPG keyring |
28 | | - run: | |
29 | | - rm -rf ~/.gnupg |
30 | | -
|
31 | | - - name: Import GPG key |
32 | | - run: | |
33 | | - echo "$GPG_PRIVATE_KEY" | gpg --batch --yes --import |
34 | | - gpg --list-keys |
35 | | - env: |
36 | | - GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} |
37 | | - |
38 | | - - name: Set GPG passphrase |
39 | | - run: echo "MAVEN_GPG_PASSPHRASE=${{ secrets.GPG_PASSPHRASE }}" >> $GITHUB_ENV |
40 | | - |
41 | | - - name: Set Default GPG Key |
42 | | - run: | |
43 | | - echo "$GPG_PRIVATE_KEY" | gpg --batch --import |
44 | | - gpg --default-key "$GPG_KEYNAME" --list-secret-keys |
45 | | - env: |
46 | | - GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} |
47 | | - GPG_KEYNAME: ${{ secrets.GPG_KEYNAME }} |
48 | | - |
49 | | - - name: Set version |
50 | | - run: mvn versions:set -DnewVersion=${{ github.event.release.tag_name }} |
51 | | - |
52 | | - - name: Publish to Maven Central |
53 | | - run: mvn --batch-mode deploy -P release -Dgpg.passphrase=${{ secrets.GPG_PASSPHRASE }} -Dgpg.keyname=${{ secrets.GPG_KEYNAME }} |
54 | | - env: |
55 | | - MAVEN_CENTRAL_USERNAME: ${{ secrets.MAVEN_CENTRAL_USERNAME }} |
56 | | - MAVEN_CENTRAL_TOKEN: ${{ secrets.MAVEN_CENTRAL_TOKEN }} |
57 | | - GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} |
58 | | - GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} |
59 | | - GPG_KEYNAME: ${{ secrets.GPG_KEYNAME }} |
| 12 | + - uses: actions/checkout@v3 |
| 13 | + |
| 14 | + - name: Import GPG key |
| 15 | + run: | |
| 16 | + echo "$GPG_PRIVATE_KEY" | base64 --decode | gpg --batch --yes --import |
| 17 | + env: |
| 18 | + GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} |
| 19 | + |
| 20 | + - name: Set up gpg-agent |
| 21 | + run: | |
| 22 | + echo "allow-loopback-pinentry" >> ~/.gnupg/gpg-agent.conf |
| 23 | + echo RELOADAGENT | gpg-connect-agent |
| 24 | + echo -e "pinentry-mode loopback\n" >> ~/.gnupg/gpg.conf |
| 25 | +
|
| 26 | + - name: Build with Maven |
| 27 | + run: | |
| 28 | + mvn clean deploy -Dgpg.passphrase=$GPG_PASSPHRASE \ |
| 29 | + -Dgpg.keyname=$GPG_KEY_ID \ |
| 30 | + -Dgpg.executable=gpg \ |
| 31 | + -Dgpg.pinentry.mode=loopback |
| 32 | + env: |
| 33 | + GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} |
| 34 | + GPG_KEY_ID: ${{ secrets.GPG_KEY_ID }} |
0 commit comments