feat: Update recommended configuration for GPG signing - #608
Conversation
This attempts to document the new recommended configuration to sign artifacts with the maven-gpg-plugin as part of the deploy process. It imitates this PR from the maintainer of the maven-gpg-plugin: https://github.com/xerial/sqlite-jdbc/pull/1082/files Notes that this requires the maven-gpg-plugin version 3.2.0 or above, not sure if this is worth adding to the documentation as I expect this guide will mostly be followed by people setting up a new project (hopefully using the latest version of the plugin by default). @cstamas I hope I got it right, feel free to suggest any improvements
cstamas
left a comment
There was a problem hiding this comment.
LGTM, but this would work with 3.2.0 m-gpg-p only of course.
|
With the release of the 3.2.1 version of the maven-gpg-plugin, this documentation update is less important as 3.2.1 will continue to work like the previous versions. However, on the long term, this would likely still be a better choice than the current set up, as it removes the dependency on an external GPG agent. Arguably setup-java shouldn't have anything to do with setting up a GPG environment as it's unrelated to Java. One downside of this method is the additional |
|
Note: 3.2.1 is out, that restores "old way" working. Still, I'd emphasize that with 3.2.x plugins, the "preferred" way of signing on CI like environments is using BC and passing secrets (key and passphrase) as environment variables. No more hoops and loops, like installing key into GnuPG and getting passphrase via crafted settings.xml should be needed. Ideally, no secret should get onto any disk/persistent storage. |
… to work (#260) related issue : #257 see a few related discussions here * https://issues.apache.org/jira/browse/MGPG-90 * actions/setup-java#608
… GPG signing (#261) see the related issue #257 see the related docs PR actions/setup-java#608
|
The recommendation is useful, but current docs intentionally cover the setup-java-managed GPG path. Recommendation: decide whether to document the BC signer flow as an additional/alternative path in a fresh docs PR. |
There was a problem hiding this comment.
Pull request overview
Updates the Maven publishing documentation to reflect a newer recommended GPG-signing approach (using maven-gpg-plugin’s Bouncy Castle signer) rather than importing a key into the runner’s GPG keychain via setup-java.
Changes:
- Removes
gpg-private-key/gpg-passphraseinputs from the Maven Centralsetup-javaexample. - Updates the deploy command to use
-Dgpg.signer=bcand passes the signing key + passphrase via environment variables. - Removes the
gpg.passphraseserver snippet and the older “extra pom.xml setup” guidance from the Maven section.
Show a summary per file
| File | Description |
|---|---|
docs/advanced-usage.md |
Refreshes the Maven Central publishing example to use maven-gpg-plugin’s BC signer workflow and updates the accompanying settings.xml examples accordingly. |
Copilot's findings
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 1/1 changed files
- Comments generated: 1
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
- Remove leftover gpg.passphrase server from the GitHub Packages settings.xml example - Clarify that the bc signer needs no gpg binary, keychain import, or pinentry loopback - Document the legacy gpg-private-key/gpg-passphrase input path alongside it - Note the MAVEN_GPG_KEY must be an ASCII-armored (TSK) secret key Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 50be9bf4-3414-43f2-8454-03c2d9e61973
Restore a complete, clearly-labeled legacy path (setup-java gpg-private-key/ gpg-passphrase inputs) for maven-gpg-plugin < 3.2.0 or the gpg executable: full workflow YAML, the generated gpg.passphrase server, and the --pinentry-mode loopback pom.xml snippet. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 50be9bf4-3414-43f2-8454-03c2d9e61973
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5.7.0 to 6.0.0. Release notes *Sourced from [actions/setup-java's releases](https://github.com/actions/setup-java/releases).* > v6.0.0 > ------ > > What's Changed > -------------- > > * dist: Migrate from Zulu Discovery API to Azul Metadata API by [`@jameswald`](https://github.com/jameswald) in [actions/setup-java#1010](https://redirect.github.com/actions/setup-java/pull/1010) > * feat: add .mvn/extensions.xml to Maven cache key pattern by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1041](https://redirect.github.com/actions/setup-java/pull/1041) > * Migrate to ESM and upgrade dependencies by [`@priyagupta108`](https://github.com/priyagupta108) in [actions/setup-java#1078](https://redirect.github.com/actions/setup-java/pull/1078) > * Map Zulu x86 architecture to i686 for Azul Metadata API by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1079](https://redirect.github.com/actions/setup-java/pull/1079) > * Rename jdkFile input to jdk-file with deprecated alias by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1083](https://redirect.github.com/actions/setup-java/pull/1083) > * Infer distribution from asdf .tool-versions vendor prefix by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1084](https://redirect.github.com/actions/setup-java/pull/1084) > * Add Maven compiler problem matcher for javac diagnostics by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1086](https://redirect.github.com/actions/setup-java/pull/1086) > * feat: expose cache-primary-key output ([#597](https://redirect.github.com/actions/setup-java/issues/597)) by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1088](https://redirect.github.com/actions/setup-java/pull/1088) > * docs: clarify V6 ESM migration is not a user-facing breaking change by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1090](https://redirect.github.com/actions/setup-java/pull/1090) > * Support multi-field Java versions like `18.0.1.1` by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1092](https://redirect.github.com/actions/setup-java/pull/1092) > * docs: document seeding the Maven cache for plugin dependencies by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1094](https://redirect.github.com/actions/setup-java/pull/1094) > * docs: clarify Maven cache paths and key hash inputs by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1096](https://redirect.github.com/actions/setup-java/pull/1096) > * Support pinning java-version as "latest" by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1093](https://redirect.github.com/actions/setup-java/pull/1093) > * chore(deps-dev): bump eslint from 10.6.0 to 10.7.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1101](https://redirect.github.com/actions/setup-java/pull/1101) > * chore(deps-dev): bump eslint-plugin-n from 18.2.1 to 18.2.2 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1103](https://redirect.github.com/actions/setup-java/pull/1103) > * chore(deps-dev): bump prettier from 3.9.4 to 3.9.5 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1105](https://redirect.github.com/actions/setup-java/pull/1105) > * chore(deps): bump actions/checkout from 6 to 7 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1106](https://redirect.github.com/actions/setup-java/pull/1106) > * chore(deps-dev): bump `@types/node` from 26.1.0 to 26.1.1 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1104](https://redirect.github.com/actions/setup-java/pull/1104) > * dist: Cover Tencent Kona JDK 25 by [`@johnshajiang`](https://github.com/johnshajiang) in [actions/setup-java#1108](https://redirect.github.com/actions/setup-java/pull/1108) > * chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1102](https://redirect.github.com/actions/setup-java/pull/1102) > * Preserve Maven toolchains across repeated setup-java runs ([#1099](https://redirect.github.com/actions/setup-java/issues/1099)) by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1111](https://redirect.github.com/actions/setup-java/pull/1111) > * dist: Support Liberica NIK ([#878](https://redirect.github.com/actions/setup-java/issues/878)) by [`@asm0dey`](https://github.com/asm0dey) in [actions/setup-java#1112](https://redirect.github.com/actions/setup-java/pull/1112) > * Fix template injection (zizmor alert [#118](https://redirect.github.com/actions/setup-java/issues/118)) in e2e-versions.yml by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1114](https://redirect.github.com/actions/setup-java/pull/1114) > * Fix template injection in e2e-versions.yml (zizmor alert [#122](https://redirect.github.com/actions/setup-java/issues/122)) by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1120](https://redirect.github.com/actions/setup-java/pull/1120) > * Disable persisted checkout credentials in e2e workflow by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1115](https://redirect.github.com/actions/setup-java/pull/1115) > * feat: Update recommended configuration for GPG signing by [`@wetneb`](https://github.com/wetneb) in [actions/setup-java#608](https://redirect.github.com/actions/setup-java/pull/608) > * Cache Maven and Gradle wrapper distributions separately from the dependency cache by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1097](https://redirect.github.com/actions/setup-java/pull/1097) > * Consolidate cache-dependency-path e2e workflow and add maven/sbt coverage by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1124](https://redirect.github.com/actions/setup-java/pull/1124) > * Use gpg.passphraseEnvName instead of the deprecated gpg.passphrase server by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1123](https://redirect.github.com/actions/setup-java/pull/1123) > * Extract repeated directory-check assertions into check-dir.sh helper by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1127](https://redirect.github.com/actions/setup-java/pull/1127) > * Consolidate duplicate jobs in e2e-versions workflow by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1125](https://redirect.github.com/actions/setup-java/pull/1125) > * Use YAML anchors to reduce boilerplate in e2e-versions workflow by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1126](https://redirect.github.com/actions/setup-java/pull/1126) > * Updated msft json for now by [`@jmjaffe37`](https://github.com/jmjaffe37) in [actions/setup-java#1129](https://redirect.github.com/actions/setup-java/pull/1129) > * Document missing action inputs in README by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1130](https://redirect.github.com/actions/setup-java/pull/1130) > * chore(deps): bump `@actions/cache` to 6.2.0 by [`@philip-gai`](https://github.com/philip-gai) in [actions/setup-java#1128](https://redirect.github.com/actions/setup-java/pull/1128) > * Add an option to disable Java problem matchers by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1133](https://redirect.github.com/actions/setup-java/pull/1133) > * docs: update setup-java examples by [`@HarithaVattikuti`](https://github.com/HarithaVattikuti) in [actions/setup-java#1131](https://redirect.github.com/actions/setup-java/pull/1131) > * Clarify credential environment variable inputs by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1134](https://redirect.github.com/actions/setup-java/pull/1134) > * chore(deps-dev): bump `@typescript-eslint/eslint-plugin` from 8.63.0 to 8.64.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1135](https://redirect.github.com/actions/setup-java/pull/1135) > * chore(deps): bump actions/setup-python from 6 to 7 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1143](https://redirect.github.com/actions/setup-java/pull/1143) > * chore(deps): bump fast-xml-parser from 5.9.3 to 5.10.1 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1142](https://redirect.github.com/actions/setup-java/pull/1142) > * chore(deps-dev): bump `@typescript-eslint/parser` from 8.64.0 to 8.65.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1138](https://redirect.github.com/actions/setup-java/pull/1138) > * chore(deps-dev): bump lint-staged from 17.0.8 to 17.2.0 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1136](https://redirect.github.com/actions/setup-java/pull/1136) > * chore(deps-dev): bump typescript from 6.0.3 to 7.0.2 by [`@dependabot`](https://github.com/dependabot)[bot] in [actions/setup-java#1137](https://redirect.github.com/actions/setup-java/pull/1137) > * chore(deps): fix npm audited vulnerabilities by [`@mhoffrog`](https://github.com/mhoffrog) in [actions/setup-java#1140](https://redirect.github.com/actions/setup-java/pull/1140) > * Fix formatting issues in README.md by [`@brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1144](https://redirect.github.com/actions/setup-java/pull/1144) > * Remediate npm audit findings and rebuild distributions by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1145](https://redirect.github.com/actions/setup-java/pull/1145) > * Set GRAALVM\_HOME for GraalVM distributions by [`@brunoborges`](https://github.com/brunoborges) with [`@Copilot`](https://github.com/Copilot) in [actions/setup-java#1146](https://redirect.github.com/actions/setup-java/pull/1146) ... (truncated) Commits * [`dd06d9c`](actions/setup-java@dd06d9c) Prepare documentation for v6 release ([#1253](https://redirect.github.com/actions/setup-java/issues/1253)) * [`59b3450`](actions/setup-java@59b3450) chore(deps): combine open Dependabot npm updates ([#1252](https://redirect.github.com/actions/setup-java/issues/1252)) * [`b96213d`](actions/setup-java@b96213d) Set default signature verification for supported distributions ([#1246](https://redirect.github.com/actions/setup-java/issues/1246)) * [`1dbac3c`](actions/setup-java@1dbac3c) docs: expose contributing guide to GitHub ([#1245](https://redirect.github.com/actions/setup-java/issues/1245)) * [`11741d6`](actions/setup-java@11741d6) ci: constrain cache e2e job modes ([#1244](https://redirect.github.com/actions/setup-java/issues/1244)) * [`ff99aa1`](actions/setup-java@ff99aa1) Fix Oracle macOS E2E version ([#1243](https://redirect.github.com/actions/setup-java/issues/1243)) * [`416c6d1`](actions/setup-java@416c6d1) Add Red Hat Build of OpenJDK support ([#1241](https://redirect.github.com/actions/setup-java/issues/1241)) * [`5f75b27`](actions/setup-java@5f75b27) Add Maven dependency-resolution repositories ([#1240](https://redirect.github.com/actions/setup-java/issues/1240)) * [`a42a52c`](actions/setup-java@a42a52c) Add multiple Maven server credentials ([#1239](https://redirect.github.com/actions/setup-java/issues/1239)) * [`fb4abd7`](actions/setup-java@fb4abd7) test: cover JDK 26 from SDKMAN ([#1238](https://redirect.github.com/actions/setup-java/issues/1238)) * Additional commits viewable in [compare view](actions/setup-java@b6effb0...dd06d9c) [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- Dependabot commands and options You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
This attempts to document the new recommended configuration to sign artifacts with the maven-gpg-plugin as part of the deploy process.
It imitates this PR from the maintainer of the maven-gpg-plugin: https://github.com/xerial/sqlite-jdbc/pull/1082/files
Notes that this requires the maven-gpg-plugin version 3.2.0 or above, not sure if this is worth adding to the documentation as I expect this guide will mostly be followed by people setting up a new project (hopefully using the latest version of the plugin by default).
@cstamas I hope I got it right, feel free to suggest any improvements
Related issue:
might be related to #600?
see also https://issues.apache.org/jira/browse/MGPG-90?page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel&focusedCommentId=17825880
Check list: