Artifacts are published to Maven Central via the
vanniktech maven-publish plugin,
targeting the Sonatype Central Portal under the org.ical4j namespace.
| Trigger | Workflow | Result |
|---|---|---|
Push to develop |
publish-snapshots.yml |
Publishes -SNAPSHOT artifacts to the Central Portal snapshot repository |
Push tag ical4j-integration-X.Y.Z (not -pre) |
publish-release.yml |
Publishes signed release artifacts and auto-releases them to Maven Central |
Push tag ical4j-integration-X.Y.Z (not -pre) |
create-release.yml |
Creates the GitHub Release (runs independently of the Central publish) |
publish-release.yml can also be run manually via workflow_dispatch.
Snapshots must be enabled for the
org.ical4jnamespace in the Central Portal (central.sonatype.com → namespace settings) before snapshot publishing will succeed. Snapshot publishing to the Central Portal requires the vanniktech plugin 0.31.0+ (this project uses 0.34.0, which requires Gradle 8.5+).
The release version is derived from the tag by the
axion-release plugin, so the publish
jobs check out with fetch-depth: 0 to make tags available.
| Secret | Purpose |
|---|---|
CENTRAL_PORTAL_USERNAME |
Central Portal token username (from the user token at central.sonatype.com → Account → Generate User Token) |
CENTRAL_PORTAL_PASSWORD |
Central Portal token password |
GPG_SIGNING_KEY |
ASCII-armored GPG private key used to sign artifacts |
GPG_SIGNING_PASSWORD |
Passphrase for the GPG key |
These are consumed by Gradle as ORG_GRADLE_PROJECT_* environment variables
(mavenCentralUsername, mavenCentralPassword, signingInMemoryKey,
signingInMemoryKeyPassword).
# list keys to find the key id
gpg --list-secret-keys --keyid-format=long
# export the private key in ASCII-armored form (this is the value for GPG_SIGNING_KEY)
gpg --armor --export-secret-keys <KEY_ID>
# publish the public key so Central can verify signatures
gpg --keyserver keyserver.ubuntu.com --send-keys <KEY_ID>Paste the full block (including the -----BEGIN/END PGP PRIVATE KEY BLOCK----- lines)
into the GPG_SIGNING_KEY secret.
- Ensure
developis green and ready. - Create and push a release tag, e.g.
git tag ical4j-integration-1.2.0 && git push origin ical4j-integration-1.2.0. publish-release.ymlsigns and publishes to Maven Central;create-release.ymldrafts the GitHub Release.
./gradlew publishToMavenLocalinspects the generated POM, jars (main + sources + javadoc), and signatures under
~/.m2/repository/org/ical4j/.