From 1366aad1347c20d2c6e1a2a82c4b5da5076d6deb Mon Sep 17 00:00:00 2001 From: kridai Date: Mon, 5 Oct 2026 14:22:26 +0530 Subject: [PATCH] chore: migrate publishing to Maven Central and harden GitHub Actions - Replace nexus-staging-maven-plugin (OSSRH, shut down) with central-publishing-maven-plugin 0.8.0 - Drop the deprecated org.sonatype.oss:oss-parent parent POM - Add the block required by Central Portal validation - Pin all actions to commit SHAs, add per-job permissions, run on ubuntu-x64 - Use twilio/sdk-actions semantic-pr-title and github-release - Comment out Slack notifications and the Datadog release metric - Replace update-dependencies workflow with Dependabot (maven + github-actions) - Update LICENSE year so LicenseTest passes Co-Authored-By: Claude Opus 5.5 --- .github/dependabot.yml | 10 +++ .github/workflows/pr-lint.yml | 19 ++++-- .github/workflows/test-and-deploy.yml | 75 +++++++++++++---------- .github/workflows/update-dependencies.yml | 60 ------------------ LICENSE | 2 +- pom.xml | 25 ++++---- 6 files changed, 80 insertions(+), 111 deletions(-) create mode 100644 .github/dependabot.yml delete mode 100644 .github/workflows/update-dependencies.yml diff --git a/.github/dependabot.yml b/.github/dependabot.yml new file mode 100644 index 0000000..c9b2105 --- /dev/null +++ b/.github/dependabot.yml @@ -0,0 +1,10 @@ +version: 2 +updates: + - package-ecosystem: "github-actions" + directory: "/" + schedule: + interval: "weekly" + - package-ecosystem: "maven" + directory: "/" + schedule: + interval: "weekly" diff --git a/.github/workflows/pr-lint.yml b/.github/workflows/pr-lint.yml index 2f5232b..c4d5693 100644 --- a/.github/workflows/pr-lint.yml +++ b/.github/workflows/pr-lint.yml @@ -3,13 +3,22 @@ on: pull_request_target: types: [ opened, edited, synchronize, reopened ] +permissions: + contents: read + pull-requests: read + jobs: validate: name: Validate title - runs-on: ubuntu-latest + runs-on: ubuntu-x64 steps: - - uses: amannn/action-semantic-pull-request@v4 + - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 + - uses: twilio/sdk-actions/semantic-pr-title@09631bfa50f14d276170d45bc4f49a80da201cc6 # main @ 09631bf — sdk-actions#10; repin to the v1.1.0 tag once cut with: - types: chore docs fix feat test misc - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + types: | + chore + docs + fix + feat + misc + test diff --git a/.github/workflows/test-and-deploy.yml b/.github/workflows/test-and-deploy.yml index 9abc8c2..2c2b335 100644 --- a/.github/workflows/test-and-deploy.yml +++ b/.github/workflows/test-and-deploy.yml @@ -13,16 +13,19 @@ on: jobs: test: name: Test - runs-on: ubuntu-latest + runs-on: ubuntu-x64 + if: github.repository_owner == 'sendgrid' timeout-minutes: 20 + permissions: + contents: read strategy: matrix: java: [ 8, 11, 17 ] steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - name: Set up Java - uses: actions/setup-java@v2 + uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1 with: distribution: 'temurin' java-version: ${{ matrix.java }} @@ -34,18 +37,23 @@ jobs: deploy: name: Deploy - if: success() && github.ref_type == 'tag' + if: success() && github.ref_type == 'tag' && github.repository_owner == 'sendgrid' needs: [ test ] - runs-on: ubuntu-latest + runs-on: ubuntu-x64 + permissions: + contents: write steps: - - uses: actions/checkout@v2 + - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 + with: + # The release action verifies refs/tags/ in the local clone. + fetch-depth: 0 - name: Set up Sonatype Maven - uses: actions/setup-java@v2 + uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # v4.7.1 with: - java-version: 8 + java-version: '8' distribution: temurin - server-id: ossrh + server-id: central server-username: MAVEN_USERNAME server-password: MAVEN_PASSWORD gpg-private-key: ${{ secrets.GPG_PRIVATE_KEY }} @@ -55,12 +63,11 @@ jobs: run: make install - name: Create GitHub Release - uses: sendgrid/dx-automator/actions/release@main + uses: twilio/sdk-actions/github-release@9b1c3222c9ffe38aadedb11c5b9f5a172b5e9951 # v1 with: assets: java-http-client.jar - footer: '**[Maven](https://mvnrepository.com/artifact/com.sendgrid/java-http-client/${version})**' - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + changelog-file: CHANGELOG.md + footer: '**[Maven](https://mvnrepository.com/artifact/com.sendgrid/java-http-client/${{ github.ref_name }})**' - name: Publish to Maven env: @@ -69,25 +76,25 @@ jobs: GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} run: mvn clean deploy -DskipTests=true -B -U -Prelease - - name: Submit metric to Datadog - uses: sendgrid/dx-automator/actions/datadog-release-metric@main - env: - DD_API_KEY: ${{ secrets.DATADOG_API_KEY }} +# - name: Submit metric to Datadog +# uses: sendgrid/dx-automator/actions/datadog-release-metric@08b601b726671445abc798ed59881766ec8fefc6 # main +# env: +# DD_API_KEY: ${{ secrets.DATADOG_API_KEY }} - notify-on-failure: - name: Slack notify on failure - if: failure() && github.event_name != 'pull_request' && (github.ref == 'refs/heads/main' || github.ref_type == 'tag') - needs: [ test, deploy ] - runs-on: ubuntu-latest - steps: - - uses: rtCamp/action-slack-notify@v2 - env: - SLACK_COLOR: failure - SLACK_ICON_EMOJI: ':github:' - SLACK_MESSAGE: ${{ format('Test *{0}*, Deploy *{1}*, {2}/{3}/actions/runs/{4}', needs.test.result, needs.deploy.result, github.server_url, github.repository, github.run_id) }} - SLACK_TITLE: Action Failure - ${{ github.repository }} - SLACK_USERNAME: GitHub Actions - SLACK_MSG_AUTHOR: twilio-dx - SLACK_FOOTER: Posted automatically using GitHub Actions - SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} - MSG_MINIMAL: true +# notify-on-failure: +# name: Slack notify on failure +# if: failure() && github.event_name != 'pull_request' && (github.ref == 'refs/heads/main' || github.ref_type == 'tag') +# needs: [ test, deploy ] +# runs-on: ubuntu-x64 +# steps: +# - uses: rtCamp/action-slack-notify@e31e87e03dd19038e411e38ae27cbad084a90661 # v2.3.3 +# env: +# SLACK_COLOR: failure +# SLACK_ICON_EMOJI: ':github:' +# SLACK_MESSAGE: ${{ format('Test *{0}*, Deploy *{1}*, {2}/{3}/actions/runs/{4}', needs.test.result, needs.deploy.result, github.server_url, github.repository, github.run_id) }} +# SLACK_TITLE: Action Failure - ${{ github.repository }} +# SLACK_USERNAME: GitHub Actions +# SLACK_MSG_AUTHOR: twilio-dx +# SLACK_FOOTER: Posted automatically using GitHub Actions +# SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} +# MSG_MINIMAL: true diff --git a/.github/workflows/update-dependencies.yml b/.github/workflows/update-dependencies.yml deleted file mode 100644 index 35ec8ed..0000000 --- a/.github/workflows/update-dependencies.yml +++ /dev/null @@ -1,60 +0,0 @@ -name: Update dependencies -on: - schedule: - # Run automatically at 7AM PST Tuesday - - cron: '0 14 * * 2' - workflow_dispatch: - -jobs: - update-dependencies-and-test: - name: Update Dependencies & Test - runs-on: ubuntu-latest - timeout-minutes: 20 - strategy: - max-parallel: 1 - matrix: - java: [ 8, 11, 17 ] - - steps: - - name: Checkout java-http-client - uses: actions/checkout@v2 - - - name: Set up Java - uses: actions/setup-java@v2 - with: - distribution: 'temurin' - java-version: ${{ matrix.java }} - cache: 'maven' - - - name: Updating semver dependencies - run: make update-deps - - - run: mvn install -Dgpg.skip -Dmaven.javadoc.skip=true -B -V - - - name: Add & Commit - if: matrix.java == '17' - uses: EndBug/add-and-commit@v8.0.2 - env: - GITHUB_TOKEN: ${{ secrets.SG_JAVA_GITHUB_TOKEN }} - with: - add: 'pom.xml' - default_author: 'github_actions' - message: 'chore: update java-http-client dependencies' - - notify-on-failure: - name: Slack notify on failure - if: failure() - needs: [ update-dependencies-and-test ] - runs-on: ubuntu-latest - steps: - - uses: rtCamp/action-slack-notify@v2 - env: - SLACK_COLOR: failure - SLACK_ICON_EMOJI: ':github:' - SLACK_MESSAGE: ${{ format('Update dependencies *{0}*, {1}/{2}/actions/runs/{3}', needs.update-dependencies-and-test.result, github.server_url, github.repository, github.run_id) }} - SLACK_TITLE: Action Failure - ${{ github.repository }} - SLACK_USERNAME: GitHub Actions - SLACK_MSG_AUTHOR: twilio-dx - SLACK_FOOTER: Posted automatically using GitHub Actions - SLACK_WEBHOOK: ${{ secrets.SLACK_WEBHOOK }} - MSG_MINIMAL: true diff --git a/LICENSE b/LICENSE index 3154774..fa5602b 100644 --- a/LICENSE +++ b/LICENSE @@ -1,6 +1,6 @@ MIT License -Copyright (C) 2023, Twilio SendGrid, Inc. +Copyright (C) 2026, Twilio SendGrid, Inc. Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in diff --git a/pom.xml b/pom.xml index efcc8d7..35a6d42 100644 --- a/pom.xml +++ b/pom.xml @@ -1,11 +1,6 @@ 4.0.0 - - org.sonatype.oss - oss-parent - 7 - com.sendgrid java-http-client jar @@ -20,6 +15,15 @@ repo + + + api + Twilio API + api@twilio.com + Twilio, Inc. + https://www.twilio.com + + https://github.com/sendgrid/java-http-client scm:git:git@github.com:sendgrid/java-http-client.git @@ -37,14 +41,13 @@ - org.sonatype.plugins - nexus-staging-maven-plugin - 1.6.8 + org.sonatype.central + central-publishing-maven-plugin + 0.8.0 true - ossrh - https://oss.sonatype.org/ - true + central + true