Repository navigation
CI: pass -Dmaven.repository.credentialScope=id to every deploy (Maven 3.10) - #215
Merged
Merged
Conversation
The runners moved to Maven 3.10, which sends a server's credentials only to the origins declared for it. For the id `central` that is repo.maven.apache.org, so the snapshot upload to central.sonatype.com/repository/maven-snapshots/ went out anonymously and failed with HTTP 401 (java-llama.cpp run 37643964068, "Not using credentials of server 'central'"). credentialScope=id is Maven's own switch back to id-only matching; replace it with setup-java's mvn-server-repository-origins once a release ships that input. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
bernardladenthin
had a problem deploying
to
maven-central
October 7, 2026 19:34 — with
GitHub Actions
Failure
bernardladenthin
had a problem deploying
to
maven-central
October 7, 2026 19:34 — with
GitHub Actions
Failure
Review SummaryThis PR correctly addresses a Maven 3.10 compatibility issue affecting snapshot and release deployments. Strengths:
Minor issues:
Security: No concerns. The change maintains the same credential scoping semantics using Maven's id-based matching as a temporary compatibility workaround. |
| # (waitUntil/waitMaxTime etc.) is visible for debugging. | ||
| - name: Show effective POM (debug) | ||
| run: mvn --batch-mode --no-transfer-progress -P release help:effective-pom | ||
| # -Dmaven.repository.credentialScope=id: see the first deploy step of this file (Maven 3.10). |
There was a problem hiding this comment.
The reference to "the first deploy step of this file" is vague. Consider being more explicit:
Suggested change
| # -Dmaven.repository.credentialScope=id: see the first deploy step of this file (Maven 3.10). | |
| # -Dmaven.repository.credentialScope=id: see the snapshot deploy step comment above for details (Maven 3.10). |
This clarifies which step to refer to.
Comment on lines
+560
to
+561
| # Restores id-only matching; replace with setup-java's `mvn-server-repository-origins: | ||
| # central:https://central.sonatype.com` once a release of setup-java ships that input. |
There was a problem hiding this comment.
The suggested replacement spans lines awkwardly. Consider one of these clearer alternatives:
Option 1 (single line):
Suggested change
| # Restores id-only matching; replace with setup-java's `mvn-server-repository-origins: | |
| # central:https://central.sonatype.com` once a release of setup-java ships that input. | |
| # Restores id-only matching; replace with setup-java's mvn-server-repository-origins once a release ships that input. |
Option 2 (more explicit):
Suggested change
| # Restores id-only matching; replace with setup-java's `mvn-server-repository-origins: | |
| # central:https://central.sonatype.com` once a release of setup-java ships that input. | |
| # Restores id-only matching; replace with setup-java's mvn-server-repository-origins once a release ships that input | |
| # (with central:https://central.sonatype.com as the target). |
This makes the intended future state clearer.
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
<server>'s credentials only to its declared origins. For the idcentralthat ishttps://repo.maven.apache.org, so a snapshot upload tocentral.sonatype.com/repository/maven-snapshots/goes out without credentials and fails with HTTP 401. java-llama.cpp hit this in run 37643964068 ("Not using credentials of server 'central' …").-Dmaven.repository.credentialScope=id, Maven's own switch back to id-only matching. The workflow comment says to replace it with setup-java'smvn-server-repository-originsonce a setup-java release ships that input (feat: support Maven server credential origins actions/setup-java#1282 is merged but not released).Test plan
check-run-scripts.py,check-shared-files.pyandcheck-release-gate.pyreport nothing.main, so the PR cannot verify it.Related issues / PRs
Same change as the java-llama.cpp PR.
Checklist
CONTRIBUTING.mdandCODE_OF_CONDUCT.mdCI:prefix instead.🤖 Generated with Claude Code
https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
Generated by Claude Code