Skip to content

Commit 9c98a31

Browse files
committed
Sign the Gradle plugins on the Plugin Portal with the release key
The Plugin Portal copies of the plugins had no signatures, while Maven Central and the GitHub release carry one for every file. With the signing plugin applied, plugin-publish signs the plugin's publications and uploads the signatures of its jars and POM along with them. The release job passes the key from the same two secrets JReleaser uses. Without the key nothing is signed, and publishPlugins refuses to publish. Checked with another RSA key, since only the release job holds the release key. The staging repository gets a signature for the jar, the sources, the javadoc, the POM, the module and the four marker POMs. publishPlugins --validate-only passes. Without the key the signing tasks are skipped, --validate-only still passes, and a real publishPlugins stops with the new error. :gradle-open-java-format:check passes.
1 parent da12ddc commit 9c98a31

2 files changed

Lines changed: 27 additions & 7 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,9 +8,9 @@ name: Release
88
# validated first, and the publish job publishes both only once both are in. A version whose native build
99
# fails publishes nothing, and its deployments can be dropped in the Portal.
1010
#
11-
# Once Maven Central serves both, the Gradle plugins go to the Gradle Plugin Portal. After publishing, a
12-
# draft GitHub release on the tag collects the runnable jar, the Gradle and IDE plugins and the native
13-
# binaries.
11+
# Once Maven Central serves both, the Gradle plugins go to the Gradle Plugin Portal, signed with the same
12+
# release key. After publishing, a draft GitHub release on the tag collects the runnable jar, the Gradle
13+
# and IDE plugins and the native binaries.
1414
#
1515
# Needs six repository secrets: JRELEASER_MAVENCENTRAL_USERNAME and JRELEASER_MAVENCENTRAL_PASSWORD (the
1616
# Central Portal user token), JRELEASER_GPG_SECRET_KEY and JRELEASER_GPG_PASSPHRASE, and
@@ -262,11 +262,13 @@ jobs:
262262
done
263263
done
264264
265-
- name: Publish the Gradle plugins
265+
- name: Sign and publish the Gradle plugins
266266
run: ./gradlew :gradle-open-java-format:publishPlugins
267267
env:
268268
GRADLE_PUBLISH_KEY: ${{ secrets.GRADLE_PUBLISH_KEY }}
269269
GRADLE_PUBLISH_SECRET: ${{ secrets.GRADLE_PUBLISH_SECRET }}
270+
JRELEASER_GPG_SECRET_KEY: ${{ secrets.JRELEASER_GPG_SECRET_KEY }}
271+
JRELEASER_GPG_PASSPHRASE: ${{ secrets.JRELEASER_GPG_PASSPHRASE }}
270272

271273
# What Maven Central does not carry — the runnable formatter jar, the Gradle plugins' jar, the IntelliJ
272274
# plugin zip, the Eclipse plugin jar, and every platform's native binary as a plain download — goes into

‎gradle-open-java-format/build.gradle‎

Lines changed: 21 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
// For the Gradle Plugin Portal: publishPlugins, run by the release workflow once Maven Central serves the
22
// version's jars and native images — the plugins depend on them. The key comes from GRADLE_PUBLISH_KEY and
3-
// GRADLE_PUBLISH_SECRET. It applies java-gradle-plugin and maven-publish itself.
3+
// GRADLE_PUBLISH_SECRET. It applies java-gradle-plugin and maven-publish itself, and once the signing
4+
// plugin is applied it signs what it uploads.
45
apply plugin: 'com.gradle.plugin-publish'
56
apply plugin: 'groovy'
7+
apply plugin: 'signing'
68
apply plugin: 'open-java-format.publishing-conventions'
79

810
description = 'Gradle plugins for open-java-format: formatting tasks, the Spotless step and IntelliJ configuration'
@@ -162,11 +164,27 @@ tasks.named("test").configure {
162164
}
163165
}
164166

165-
// The Portal never takes a version back, so only a release version goes up — X.Y.Z or X.Y.Z.N, as for Maven
166-
// Central in open-java-format.release-conventions. --validate-only checks the metadata of any version.
167+
// Signed with the release key, which also signs the Maven Central artifacts and the GitHub release. Only the
168+
// release job has it, in JRELEASER_GPG_SECRET_KEY and JRELEASER_GPG_PASSPHRASE; anywhere else nothing is
169+
// signed.
170+
def signingKey = providers.environmentVariable('JRELEASER_GPG_SECRET_KEY').getOrNull()
171+
def signed = signingKey != null
172+
signing {
173+
required = false
174+
if (signed) {
175+
useInMemoryPgpKeys(signingKey, providers.environmentVariable('JRELEASER_GPG_PASSPHRASE').get())
176+
}
177+
}
178+
179+
// The Portal never takes a version back, so only a signed release version goes up — X.Y.Z or X.Y.Z.N, as for
180+
// Maven Central in open-java-format.release-conventions. --validate-only checks the metadata of any version.
167181
def portalVersion = provider { project.version.toString() }
168182
tasks.named('publishPlugins') {
169183
doFirst {
184+
if (!validateOnly.getOrElse(false) && !signed) {
185+
throw new GradleException('Refusing to publish unsigned plugins to the Gradle Plugin Portal: set '
186+
+ 'JRELEASER_GPG_SECRET_KEY and JRELEASER_GPG_PASSPHRASE, or pass --validate-only.')
187+
}
170188
if (!validateOnly.getOrElse(false) && !(portalVersion.get() ==~ /\d+\.\d+\.\d+(\.\d+)?/)) {
171189
throw new GradleException("Refusing to publish ${portalVersion.get()} to the Gradle Plugin Portal: check "
172190
+ 'out a release tag on a clean working tree, or pass --validate-only.')

0 commit comments

Comments
 (0)