diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index cebed07..8f87528 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -7,4 +7,7 @@ on: jobs: ci: - uses: killbill/gh-actions-shared/.github/workflows/ci.yml@java21 + uses: killbill/gh-actions-shared/.github/workflows/ci.yml@main + secrets: + CLOUDSMITH_CENTRAL_PASSWORD: ${{ secrets.CLOUDSMITH_CENTRAL_PASSWORD }} + CLOUDSMITH_KILLBILL_MAVEN_REPO_PASSWORD: ${{ secrets.CLOUDSMITH_KILLBILL_MAVEN_REPO_PASSWORD }} diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml index b8add17..7d120c8 100644 --- a/.github/workflows/codeql-analysis.yml +++ b/.github/workflows/codeql-analysis.yml @@ -7,4 +7,7 @@ on: jobs: analyze: - uses: killbill/gh-actions-shared/.github/workflows/codeql-analysis.yml@java21 + uses: killbill/gh-actions-shared/.github/workflows/codeql-analysis.yml@main + secrets: + CLOUDSMITH_CENTRAL_PASSWORD: ${{ secrets.CLOUDSMITH_CENTRAL_PASSWORD }} + CLOUDSMITH_KILLBILL_MAVEN_REPO_PASSWORD: ${{ secrets.CLOUDSMITH_KILLBILL_MAVEN_REPO_PASSWORD }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 3b61be9..fc2b2a3 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -17,88 +17,21 @@ on: default: true type: boolean -env: - MAVEN_FLAGS: "-B --no-transfer-progress" - MAVEN_OPTS: "-Xmx2G -XX:+ExitOnOutOfMemoryError -Dmaven.wagon.rto=60000 -Dmaven.wagon.httpconnectionManager.ttlSeconds=25 -Dmaven.wagon.http.retryHandler.count=3" - jobs: release: - runs-on: ubuntu-latest - steps: - - name: Checkout code - if: github.event.inputs.perform_version == '' - uses: actions/checkout@v6 - - name: Checkout full repository - # Required when performing an existing release. - if: github.event.inputs.perform_version != '' - uses: actions/checkout@v6 - with: - fetch-depth: '0' - - name: Setup git user - env: - BUILD_USER: ${{ secrets.BUILD_USER }} - BUILD_TOKEN: ${{ secrets.BUILD_TOKEN }} - run: | - git config --global user.email "contact@killbill.io" - git config --global user.name "Kill Bill core team" - git config --global url."https://${BUILD_USER}:${BUILD_TOKEN}@github.com/".insteadOf "git@github.com:" - - name: Configure Java - uses: actions/setup-java@v5 - with: - java-version: 21 - distribution: temurin - - name: Download Java dependencies - # We do as much as we can, but it may not be enough (https://issues.apache.org/jira/browse/MDEP-82) - run: | - mvn ${MAVEN_FLAGS} clean install dependency:resolve dependency:resolve-plugins -DskipTests=true -Dgpg.skip=true -Psonatype-oss-release - - name: Update killbill-oss-parent - if: github.event.inputs.parent_version != '' - run: | - echo "Updating killbill-oss-parent pom.xml to ${{ github.event.inputs.parent_version }}:" - mvn ${MAVEN_FLAGS} versions:update-parent -DgenerateBackupPoms=false -DparentVersion="[${{ github.event.inputs.parent_version }}]" - echo "killbill-oss-parent pom.xml changes:" - git --no-pager diff - echo "Downloading new dependencies:" - mvn ${MAVEN_FLAGS} -U clean install -DskipTests=true - - git add pom.xml - # Will be pushed as part of the release process, only if the release is successful - git commit -m "pom.xml: update killbill-oss-parent to ${{ github.event.inputs.parent_version }}" - - name: Configure settings.xml for release - uses: actions/setup-java@v5 - with: - java-version: 21 - distribution: temurin - server-id: central - server-username: MAVEN_USERNAME - server-password: MAVEN_PASSWORD - gpg-private-key: ${{ secrets.GPG_SIGNING_KEY }} - gpg-passphrase: GPG_PASSPHRASE - - name: Release artifacts - if: github.event.inputs.perform_version == '' - env: - MAVEN_USERNAME: ${{ secrets.MAVEN_USERNAME }} - MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }} - GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} - # It will still check the remote but hopefully not download much (0 B at 0 B/s). -o isn't safe because of MDEP-82 (see above). - run: | - mvn ${MAVEN_FLAGS} release:clean release:prepare release:perform - - name: Perform release - if: github.event.inputs.perform_version != '' - env: - MAVEN_USERNAME: ${{ secrets.MAVEN_USERNAME }} - MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }} - GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} - # It will still check the remote but hopefully not download much (0 B at 0 B/s). -o isn't safe because of MDEP-82 (see above). - # See https://issues.apache.org/jira/browse/SCM-729 for why the release.properties file is required. - run: | - echo "scm.url=scm\:git\:git@github.com\:${GITHUB_REPOSITORY}.git" > release.properties - echo "scm.tag=${{ github.event.inputs.perform_version }}" >> release.properties - mvn ${MAVEN_FLAGS} release:perform - - name: Release killbill-oss-parent - if: github.event.inputs.release_oss_parent == 'true' - env: - GH_TOKEN: ${{ secrets.GH_WORKFLOW_PAT }} - run: | - PROJECT_VERSION=$(git describe --abbrev=0 | cut -d '-' -f 4) - gh workflow -R killbill/killbill-oss-parent run release.yml -f java_client_version=${PROJECT_VERSION} + uses: killbill/gh-actions-shared/.github/workflows/release.yml@main + with: + parent_version: ${{ github.event.inputs.parent_version }} + perform_version: ${{ github.event.inputs.perform_version }} + release_oss_parent: ${{ github.event.inputs.release_oss_parent }} + oss_parent_dispatch_property: 'java_client_version' + secrets: + BUILD_USER: ${{ secrets.BUILD_USER }} + BUILD_TOKEN: ${{ secrets.BUILD_TOKEN }} + CLOUDSMITH_CENTRAL_PASSWORD: ${{ secrets.CLOUDSMITH_CENTRAL_PASSWORD }} + CLOUDSMITH_KILLBILL_MAVEN_REPO_PASSWORD: ${{ secrets.CLOUDSMITH_KILLBILL_MAVEN_REPO_PASSWORD }} + CLOUDSMITH_DISTRIBUTION_MAN_USERNAME: ${{ secrets.CLOUDSMITH_DISTRIBUTION_MAN_USERNAME }} + CLOUDSMITH_DISTRIBUTION_MAN_PASSWORD: ${{ secrets.CLOUDSMITH_DISTRIBUTION_MAN_PASSWORD }} + GPG_SIGNING_KEY: ${{ secrets.GPG_SIGNING_KEY }} + GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} + GH_WORKFLOW_PAT: ${{ secrets.GH_WORKFLOW_PAT }} diff --git a/.github/workflows/snapshot.yml b/.github/workflows/snapshot.yml index cd51d66..d4ea57a 100644 --- a/.github/workflows/snapshot.yml +++ b/.github/workflows/snapshot.yml @@ -6,7 +6,9 @@ on: jobs: snapshot: - uses: killbill/gh-actions-shared/.github/workflows/snapshot.yml@java21 + uses: killbill/gh-actions-shared/.github/workflows/snapshot.yml@main secrets: - MAVEN_USERNAME: ${{ secrets.MAVEN_USERNAME }} - MAVEN_PASSWORD: ${{ secrets.MAVEN_PASSWORD }} + CLOUDSMITH_CENTRAL_PASSWORD: ${{ secrets.CLOUDSMITH_CENTRAL_PASSWORD }} + CLOUDSMITH_KILLBILL_MAVEN_REPO_PASSWORD: ${{ secrets.CLOUDSMITH_KILLBILL_MAVEN_REPO_PASSWORD }} + CLOUDSMITH_DISTRIBUTION_MAN_USERNAME: ${{ secrets.CLOUDSMITH_DISTRIBUTION_MAN_USERNAME }} + CLOUDSMITH_DISTRIBUTION_MAN_PASSWORD: ${{ secrets.CLOUDSMITH_DISTRIBUTION_MAN_PASSWORD }} diff --git a/.github/workflows/sync.yml b/.github/workflows/sync.yml index f044f85..724801a 100644 --- a/.github/workflows/sync.yml +++ b/.github/workflows/sync.yml @@ -7,6 +7,6 @@ on: jobs: sync: - uses: killbill/gh-actions-shared/.github/workflows/sync.yml@java21 + uses: killbill/gh-actions-shared/.github/workflows/sync.yml@main secrets: CREATE_PULL_REQUEST_SSH_KEY: ${{ secrets.CREATE_PULL_REQUEST_SSH_KEY }} diff --git a/pom.xml b/pom.xml index ac3d5f1..64cea2e 100644 --- a/pom.xml +++ b/pom.xml @@ -22,7 +22,7 @@ org.kill-bill.billing killbill-oss-parent - 0.147.19 + 0.147.27 killbill-client-java 1.5.4-SNAPSHOT