-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Fix release failure after maven central plugin migration #4432
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Fix release failure after maven central plugin migration #4432
Conversation
Signed-off-by: Min Jin <[email protected]>
Signed-off-by: Min Jin <[email protected]>
Signed-off-by: Min Jin <[email protected]>
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: yue9944882 The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
Ref: #4239 |
| ./mvnw -Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn -DlocalCheckout=true -Darguments=-DskipTests org.apache.maven.plugins:maven-release-plugin:perform | ||
| ./mvnw -s /home/runner/.m2/settings.xml -Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn -DlocalCheckout=true -Darguments=-DskipTests org.apache.maven.plugins:maven-release-plugin:perform | ||
| curl -X POST \ | ||
| -H "Authorization: Bearer $(echo ${{ secrets.SNAPSHOT_UPLOAD_USER }}:${{ secrets.SNAPSHOT_UPLOAD_PASSWORD }} | base64 -w0)" \ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Is this going to dump our password into the logs for our github actions workflows? Is there another way to do this?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
# The tests are already executed in the prepare, skipping
./mvnw -s /home/runner/.m2/settings.xml -Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn -DlocalCheckout=true -Darguments=-DskipTests org.apache.maven.plugins:maven-release-plugin:perform
curl -X POST \
-H "Authorization: *** ***:*** | base64 -w0)" \
https://ossrh-staging-api.central.sonatype.com/manual/upload/defaultRepository/io.kubernetes -v
git push https://***@github.com/kubernetes-client/java.git \
automated-release-25.0.0-legacy:automated-release-25.0.0-legacy
git push https://***@github.com/kubernetes-client/java.git v25.0.0-legacy
https://github.com/kubernetes-client/java/actions/runs/19683023331/job/56381525646
the workflow auto-redact the secrets in our workflow ^^^
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I really still don't love this, redaction should be a last resort, not an relied upon feature. There must be some way to do this without it being on the command line.
|
Looks good, but I'm worried that the current curl call is going to dump our auth info into the CI/CD logs. |
| ./mvnw -Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn -DlocalCheckout=true -Darguments=-DskipTests org.apache.maven.plugins:maven-release-plugin:perform | ||
| ./mvnw -s /home/runner/.m2/settings.xml -Dorg.slf4j.simpleLogger.log.org.apache.maven.cli.transfer.Slf4jMavenTransferListener=warn -DlocalCheckout=true -Darguments=-DskipTests org.apache.maven.plugins:maven-release-plugin:perform | ||
| curl -X POST \ | ||
| -H "Authorization: Bearer $(echo ${{ secrets.SNAPSHOT_UPLOAD_USER }}:${{ secrets.SNAPSHOT_UPLOAD_PASSWORD }} | base64 -w0)" \ |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I really still don't love this, redaction should be a last resort, not an relied upon feature. There must be some way to do this without it being on the command line.
| <!-- TODO: workaround until openapi stops generating a dependency on | ||
| the un-exported module: com.google.gson.internal.bind.util --> | ||
| <legacyMode>true</legacyMode> | ||
| <tags> |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What does this do? Is this part of the TODO above also?
This PR adds API after maven release plugin run according to: