Skip to content

Pin Maven 3.9.16 for snapshot publishing - #35

Closed
bertysentry wants to merge 1 commit into
mainfrom
fix/pin-maven-3.9.16
Closed

bertysentry wants to merge 1 commit into
mainfrom
fix/pin-maven-3.9.16

Conversation

@bertysentry

@bertysentry bertysentry commented Oct 8, 2026 •

Copy link
Copy Markdown

Superseded

Superseded by #36, merged and included in v7. The released workflow declares the Sonatype origin while keeping Maven 3.10 credential scoping enabled, so the Maven 3.9.16 pin is no longer needed. IPMI adoption is tracked in MetricsHub/ipmi-java#133.

Original proposal (not merged)

Summary

Pin snapshot publishing to Apache Maven 3.9.16 instead of inheriting the Maven version from ubuntu-latest.

The runner update to Maven 3.10.0 introduced origin-scoped credentials, which withhold the existing central credentials from central.sonatype.com. This keeps the known-good Maven version while preserving the existing settings and credentials.

  • Download the official Apache archive and verify its fixed SHA512 before extraction.
  • Put Maven 3.9.16 first on PATH and verify the selected executable in the next step.
  • Keep the change limited to the snapshot deployment workflow.

Validation

  • actionlint 1.7.12 passes for the changed workflow.
  • YAML parsing, Bash syntax and git diff --check pass.
  • Executed the installation script against the official archive; SHA512 matched.
  • Verified the resulting mvn reports 3.9.16, including an installation path containing spaces.
  • Verified the version guard rejects Maven 3.10.0.
  • Existing lint findings in the separate release workflow remain unchanged.

Rollout

Draft only. No deployment or release was run. IPMI currently calls workflows@v4, so MetricsHub/ipmi-java#133 pins this exact commit. The v4 tag is unchanged. Separate release workflows remain outside this snapshot fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant