Skip to content

ci: diagnose signing secret + sign with useInMemoryPgpKeys - #24

Merged
abueide merged 2 commits into
mainfrom
ci/debug-signing-secret
Sep 14, 2026
Merged

abueide merged 2 commits into
mainfrom
ci/debug-signing-secret

Conversation

@abueide

@abueide abueide commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds a temporary debug-signing-secret.yml workflow (workflow_dispatch) that reports whether SIGNING_KEY_ID/SIGNING_KEY_PASSWORD/SIGNING_PRIVATE_KEY_BASE64 are populated, the decoded byte length, and whether the decoded content looks like an ASCII-armored PGP key block — no key material is ever printed. Will be removed in a follow-up PR once we've confirmed what's going on.
  • Fixes publishing-plugins/src/main/kotlin/mvn-publish.gradle.kts to sign via signing.useInMemoryPgpKeys(keyId, armoredKey, password) instead of writing the decoded secret to a binary secretKeyRingFile. The latest 1.7.2 release attempt failed at :lib:signTestPublication with Unable to read secret key from file ... it may not be a PGP secret key ring — consistent with SIGNING_PRIVATE_KEY_BASE64 decoding to an ASCII-armored key block rather than a binary keyring, which Gradle's secretKeyRingFile signatory can't parse. useInMemoryPgpKeys accepts the armored text directly.

Test plan

  • Merge to main
  • Run gh workflow run debug-signing-secret.yml and confirm the secret is populated and check its format
  • Retry the 1.7.2 release (gh workflow run release.yml -f tag=1.7.2) and confirm signing succeeds
  • Follow-up PR to delete debug-signing-secret.yml once confirmed

🤖 Generated with Claude Code

Gradle's signing plugin expects signing.secretKeyRingFile to point at
a binary GPG keyring, but SIGNING_PRIVATE_KEY_BASE64 decodes to an
ASCII-armored key block, causing 'Unable to read secret key from
file ... it may not be a PGP secret key ring' during signTestPublication.
useInMemoryPgpKeys accepts the armored key text directly, sidestepping
the binary-keyring requirement.
@abueide abueide changed the title ci: temporary diagnostic for signing secret format ci: diagnose signing secret + sign with useInMemoryPgpKeys Sep 14, 2026
@abueide
abueide merged commit b8030c0 into main Sep 14, 2026
9 of 10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant