Repository navigation
Declare Central as an origin of server central for Maven 3.10 - #36
Merged
Merged
Conversation
Maven 3.10 (GitHub image ubuntu24/20261004 and later) binds the credentials of a server to the origins declared for its id, and the id "central" is bound to repo.maven.apache.org by the built-in central repository. The snapshot deploy to central.sonatype.com therefore went out without credentials and failed with HTTP 401. Add https://central.sonatype.com to the <repositoryOrigins> of server central in the settings.xml written by s4u/maven-settings-action, which cannot write that element. Origin scoping stays on, unlike -Dmaven.repository.credentialScope=id. The step fails if the server is not found. Maven 3.9 ignores the element with a warning. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
ChristopheClermont
approved these changes
Oct 8, 2026
This was referenced Oct 8, 2026
Merged
Merged
Merged
Merged
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Since GitHub runner image
ubuntu24/20261004ships Maven 3.10.0,maven-central-deploy.ymlfails atcentral-publishing:publishwithHTTP Status: 401onhttps://central.sonatype.com/repository/maven-snapshots.Maven 3.10 scopes server credentials to the origins declared for their id (
maven.repository.credentialScope=originby default). The idcentralis bound tohttps://repo.maven.apache.orgby the built-in central repository. The credentials of servercentralare therefore not sent tocentral.sonatype.com, and the log says so:Change
After
s4u/maven-settings-action, a step addshttps://central.sonatype.comto the origins of servercentralin~/.m2/settings.xml:<repositoryOrigins>. The step inserts the element after<server><id>central</id>and fails if the server is not found.scheme://host[:port], so this covers both the release URL and the snapshots URL.-Dmaven.repository.credentialScope=id, a repository namedcentralat any other origin (declared by a dependency POM, for example) does not receive the publishing token.repo.maven.apache.orgstays bound by the built-in central repository.PublishMojoreads the server directly instead of going through the resolver's origin check.This is an alternative to #35, which pins Maven 3.9.16. Maven 3.9.17 gets the same origin scoping, so pinning only delays the problem.
Validation
I simulated an s4u v4.0.0 settings.xml (from its templates) and ran the step script exactly as YAML decodes it:
central: the element is inserted exactly once, inside that server;I ran an end-to-end snapshot deploy of
simple-http-java(central-publishing0.11.0, profilemaven-central) against a local server that behaves like Central: anonymous GETs allowed, and 401 withWWW-Authenticate: BASICon anonymous PUTs. The origin was set to that server.In CI,
-Dmaven.repository.credentialScope=idalready fixed simple-http-java and jflat on Maven 3.10.0, which confirms the cause.Rollout
Callers pin a tag (
@v6; some@v4or@v2), so merging intomainis not enough. After the merge, either:v6to the merge commit, orv7and bump the callers.Then remove
mavenOptions: "-Dmaven.repository.credentialScope=id"from the callers that added it as a stopgap: simple-http-java and jflat (.github/workflows/deploy.yml).metricshub-community has its own
maven-build.yml; it gets the same step in MetricsHub/metricshub-community#1380.🤖 Generated with Claude Code