Skip to content

CI: pass -Dmaven.repository.credentialScope=id to every deploy (Maven 3.10) - #215

Merged
bernardladenthin merged 1 commit into
mainfrom
claude/hopeful-pascal-9jlbqb
Oct 7, 2026
Merged

bernardladenthin merged 1 commit into
mainfrom
claude/hopeful-pascal-9jlbqb

Conversation

@bernardladenthin

Copy link
Copy Markdown
Owner

Summary

  • The runners now ship Maven 3.10, which sends a <server>'s credentials only to its declared origins. For the id central that is https://repo.maven.apache.org, so a snapshot upload to central.sonatype.com/repository/maven-snapshots/ goes out without credentials and fails with HTTP 401. java-llama.cpp hit this in run 37643964068 ("Not using credentials of server 'central' …").
  • Both deploy steps (snapshot and release) now pass -Dmaven.repository.credentialScope=id, Maven's own switch back to id-only matching. The workflow comment says to replace it with setup-java's mvn-server-repository-origins once a setup-java release ships that input (feat: support Maven server credential origins actions/setup-java#1282 is merged but not released).

Test plan

  • check-run-scripts.py, check-shared-files.py and check-release-gate.py report nothing.
  • CI is green on this branch.
  • The snapshot deploy succeeds after merge. The upload runs only on main, so the PR cannot verify it.
  • CHANGELOG updated.

Related issues / PRs

Same change as the java-llama.cpp PR.

Checklist

  • I have read CONTRIBUTING.md and CODE_OF_CONDUCT.md
  • My commits follow Conventional Commits. They use the repository's usual CI: prefix instead.
  • No security-sensitive changes. Credentials are still scoped per step.

🤖 Generated with Claude Code

https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2


Generated by Claude Code

The runners moved to Maven 3.10, which sends a server's credentials only
to the origins declared for it. For the id `central` that is
repo.maven.apache.org, so the snapshot upload to
central.sonatype.com/repository/maven-snapshots/ went out anonymously and
failed with HTTP 401 (java-llama.cpp run 37643964068, "Not using
credentials of server 'central'"). credentialScope=id is Maven's own
switch back to id-only matching; replace it with setup-java's
mvn-server-repository-origins once a release ships that input.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
@claude

claude Bot commented Oct 7, 2026

Copy link
Copy Markdown

Review Summary

This PR correctly addresses a Maven 3.10 compatibility issue affecting snapshot and release deployments.

Strengths:

  • Correct diagnosis: Maven 3.10 restricts credentials to declared repository origins, causing deployments to the Sonatype snapshot repo to fail with HTTP 401
  • Consistent fix: Both snapshot and release deploy steps are updated with the flag
  • Clear documentation: CHANGELOG entry thoroughly explains the problem and solution
  • Path forward: Comments correctly note this is temporary until setup-java ships the mvn-server-repository-origins input
  • Proper testing: Local checks (check-shared-files.py, check-run-scripts.py) passed

Minor issues:

  1. Line 729: The release deploy comment 'see the first deploy step of this file' is vague—should reference the snapshot deploy step explicitly
  2. Lines 560-561: The suggested future replacement for setup-java spans lines awkwardly

Security: No concerns. The change maintains the same credential scoping semantics using Maven's id-based matching as a temporary compatibility workaround.

# (waitUntil/waitMaxTime etc.) is visible for debugging.
- name: Show effective POM (debug)
run: mvn --batch-mode --no-transfer-progress -P release help:effective-pom
# -Dmaven.repository.credentialScope=id: see the first deploy step of this file (Maven 3.10).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The reference to "the first deploy step of this file" is vague. Consider being more explicit:

Suggested change
# -Dmaven.repository.credentialScope=id: see the first deploy step of this file (Maven 3.10).
# -Dmaven.repository.credentialScope=id: see the snapshot deploy step comment above for details (Maven 3.10).

This clarifies which step to refer to.

Comment on lines +560 to +561
# Restores id-only matching; replace with setup-java's `mvn-server-repository-origins:
# central:https://central.sonatype.com` once a release of setup-java ships that input.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The suggested replacement spans lines awkwardly. Consider one of these clearer alternatives:

Option 1 (single line):

Suggested change
# Restores id-only matching; replace with setup-java's `mvn-server-repository-origins:
# central:https://central.sonatype.com` once a release of setup-java ships that input.
# Restores id-only matching; replace with setup-java's mvn-server-repository-origins once a release ships that input.

Option 2 (more explicit):

Suggested change
# Restores id-only matching; replace with setup-java's `mvn-server-repository-origins:
# central:https://central.sonatype.com` once a release of setup-java ships that input.
# Restores id-only matching; replace with setup-java's mvn-server-repository-origins once a release ships that input
# (with central:https://central.sonatype.com as the target).

This makes the intended future state clearer.

@bernardladenthin
bernardladenthin merged commit 09a21d2 into main Oct 7, 2026
23 of 32 checks passed
@bernardladenthin
bernardladenthin deleted the claude/hopeful-pascal-9jlbqb branch October 7, 2026 19:59

This branch had an error being deployed

1 failed and 1 active deployments
maven-central — a881826e Deployed Oct 7, 2026 by bernardladenthin via Verify GPG signing key (no secrets printed) #377
startgate — a881826e Deployed Oct 7, 2026 by bernardladenthin via Start gate (abort window) #377
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants