Skip to content

Deploy to Maven Central #2

Deploy to Maven Central

Deploy to Maven Central #2

Workflow file for this run

name: Deploy to Maven Central
env:
JAVA_VERSION: '17'
MAVEN_VERSION: '3.9.15'
on:
release:
types: ["released"]
jobs:
requires-approval:
runs-on: ubuntu-latest
name: "Waiting for release approval"
environment: release-approval
permissions:
contents: read
steps:
- name: Approval Step
run: echo "Release has been approved!"
verify-version:
needs: requires-approval
name: Verify Version Matches Tag
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
ref: ${{ github.event.release.tag_name }}
- name: Set up Java
uses: actions/setup-java@be666c2fcd27ec809703dec50e508c2fdc7f6654 # v5
with:
java-version: ${{ env.JAVA_VERSION }}
distribution: sapmachine
cache: maven
- name: Set up Maven
uses: stCarolas/setup-maven@d6af6abeda15e98926a57b5aa970a96bb37f97d1 # v5
with:
maven-version: ${{ env.MAVEN_VERSION }}
- name: Verify pom.xml revision matches release tag
env:
TAG: ${{ github.event.release.tag_name }}
run: |
REVISION=$(mvn help:evaluate -Dexpression=revision -q -DforceStdout)
echo "Tag: $TAG"
echo "Revision: $REVISION"
if [ "$TAG" != "$REVISION" ]; then
echo "::error::Release tag '$TAG' does not match pom.xml <revision> '$REVISION'. Open a 'Prep release' PR to bump the version before tagging."
exit 1
fi
shell: bash
blackduck:
needs: verify-version
name: Blackduck Scan
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
ref: ${{ github.event.release.tag_name }}
- name: Scan With Black Duck
uses: cap-java/.github/actions/scan-with-blackduck@296573b55e906f5c77a1855bcfe4285cbbc5cac4 # main
with:
blackduck_token: ${{ secrets.BLACK_DUCK_TOKEN }}
github_token: ${{ secrets.GITHUB_TOKEN }}
maven-version: ${{ env.MAVEN_VERSION }}
project-name: com.sap.cds.cds-ai
included-modules: cds-feature-ai-core,cds-feature-recommendations,cds-starter-ai
version: ${{ github.event.release.tag_name }}
build:
name: Build
runs-on: ubuntu-latest
timeout-minutes: 30
needs: verify-version
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
ref: ${{ github.event.release.tag_name }}
- name: Build
uses: cap-java/.github/actions/build@296573b55e906f5c77a1855bcfe4285cbbc5cac4 # main
with:
java-version: ${{ env.JAVA_VERSION }}
maven-version: ${{ env.MAVEN_VERSION }}
maven-args: "-P '!with-integration-tests'"
deploy:
name: Deploy to Maven Central
runs-on: ubuntu-latest
timeout-minutes: 30
needs: [blackduck, build]
environment: release
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
with:
ref: ${{ github.event.release.tag_name }}
- name: Deploy
uses: cap-java/.github/actions/deploy-release@296573b55e906f5c77a1855bcfe4285cbbc5cac4 # main
with:
user: ${{ secrets.CENTRAL_REPOSITORY_USER }}
password: ${{ secrets.CENTRAL_REPOSITORY_PASS }}
gpg-pub-key: ${{ secrets.PGP_PUBKEY_ID }}
gpg-private-key: ${{ secrets.PGP_PRIVATE_KEY }}
gpg-passphrase: ${{ secrets.PGP_PASSPHRASE }}
revision: ${{ github.event.release.tag_name }}
maven-version: ${{ env.MAVEN_VERSION }}
maven-profiles: "deploy-release,'!with-integration-tests'"