Fix Maven Central upload workflow - #25
Merged
Merged
Conversation
Add the missing public PGP key secret to the release workflow, support both tag and manual dispatch for Maven Central uploads, and prevent the draw.io export workflow from running on tag pushes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
fabiogouw
force-pushed
the
chore/jreleaser-public-key
branch
from
July 31, 2026 00:02
35573a9 to
e104bdd
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
This PR fixes the Maven Central upload workflow after the first run exposed an incomplete PGP signing setup.
What changed
JRELEASER_GPG_PUBLIC_KEYto the release workflow because JReleaser PGP memory mode requires the public key in addition to the private key and passphrasev*tag push and manual viaworkflow_dispatchwith arelease_taginputHow to use
GitHub Actions
Configure these repository secrets before running the release workflow:
MAVEN_CENTRAL_USERNAMEMAVEN_CENTRAL_PASSWORDJRELEASER_GPG_PUBLIC_KEYJRELEASER_GPG_SECRET_KEYJRELEASER_GPG_PASSPHRASEThe workflow can be triggered in two ways:
v*.release_taginput.In both cases the workflow uploads the deployment to Maven Central in
UPLOADmode, and the final publish step must still be confirmed manually in the Central Portal.Local run
Export the same Maven Central and JReleaser signing variables locally, plus
GITHUB_TOKEN, then run:If you want to force upload-only mode locally, use: