Skip to content

固定发布工作流使用 Maven 3.9.16 - #4136

Merged
binarywang merged 4 commits into
developfrom
copilot/fix-build-and-publish-job
Oct 9, 2026
Merged

binarywang merged 4 commits into
developfrom
copilot/fix-build-and-publish-job

Conversation

Copilot AI commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Maven Central 拒绝了发布工作流生成的 bundle。原因是 Runner 默认 Maven 3.10 的 Resolver 2 将仓库元数据写入 staging 目录。

  • 固定 Maven 版本:新增 Maven 3.9.16 Wrapper,并让发布步骤通过 Wrapper 执行:
    ./mvnw versions:set -DnewVersion=$VERSION
    ./mvnw clean deploy -P release

Copilot AI and others added 2 commits October 9, 2026 05:14
Co-authored-by: binarywang <1343140+binarywang@users.noreply.github.com>
Co-authored-by: binarywang <1343140+binarywang@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix failing GitHub Actions job build-and-publish 固定发布工作流使用 Maven 3.9.16 Oct 9, 2026
Copilot AI requested a review from binarywang October 9, 2026 05:16
@binarywang
binarywang marked this pull request as ready for review October 9, 2026 05:22
Copilot AI balanced review requested due to automatic review settings October 9, 2026 05:22
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-09T05:24:30.438453Z 17f435e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 17f435e7c4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@@ -0,0 +1,3 @@
wrapperVersion=3.3.4
distributionType=only-script
distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.16/apache-maven-3.9.16-bin.zip

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge 为下载的 Maven 发行包配置校验和

当 Maven Wrapper 缓存未命中时,该 URL 对应的压缩包会被直接下载、解压并执行;由于未设置 distributionSha256Sum,新增脚本中的校验分支会被跳过。发布作业同时持有 Maven Central 凭据和已导入的 GPG 私钥,因此下载源或传输链路一旦返回被篡改的归档,就可能执行任意代码并窃取发布凭据或伪造制品;请在此处固定 Apache 官方公布的 SHA-256 值,使校验失败时终止发布。

AGENTS.md reference: AGENTS.md:L104-L106

Useful? React with 👍 / 👎.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Maven 发行包缺少 SHA-256 完整性校验,会给持有发布凭据的工作流引入供应链风险。

1 open finding
What changed in this PR

该 PR 固定发布流程使用 Maven 3.9.16,避免新版 Resolver 生成不兼容的 staging bundle。

Changes:

  • 新增 Maven Wrapper。
  • 发布步骤改用 ./mvnw。
  • 固定 Maven 发行版本。
File Description
mvnw 新增 Wrapper 启动脚本
.mvn/​wrapper/​maven-wrapper.properties 固定 Maven 3.9.16
.github/​workflows/​maven-publish.yml 发布命令改用 Wrapper

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .mvn/wrapper/maven-wrapper.properties
@augmentcode

augmentcode Bot commented Oct 9, 2026

Copy link
Copy Markdown
🤖 Augment PR Summary

摘要:为 Maven Central 发布流程固定 Maven 3.9.16。
根据 PR 描述,此变更旨在避免 Runner 默认 Maven 3.10 的 Resolver 2 将仓库元数据写入 staging,导致发布 bundle 被拒绝。
变更:

  • 新增根目录 Shell 启动脚本 mvnw。
  • 新增 .mvn/wrapper/maven-wrapper.properties。
  • 采用 Maven Wrapper 3.3.4 的 only-script 分发方式。
  • 通过 Maven Central 下载 Maven 3.9.16,并缓存在用户 Maven 目录中。
  • 将版本设置与发布命令改为 ./mvnw versions:set 和 ./mvnw clean deploy -P release。
技术说明:保留现有 Java 8 环境、版本生成逻辑、GPG 签名及发布参数,不修改 SDK 业务代码。 审查结论:静态检查未发现明确需要报告的缺陷;未执行构建、测试或实际发布验证。

🤖 Was this summary useful? React with 👍 or 👎

@augmentcode augmentcode Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review completed. No suggestions at this time.

Items Reviewed
  • ✅ 核对审查规则和发布上下文
  • ✅ 逐行检查变更并验证问题

Comment augment review to trigger a new review at any time.

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@binarywang
binarywang merged commit 6b4a3d3 into develop Oct 9, 2026
1 of 2 checks passed
@binarywang
binarywang deleted the copilot/fix-build-and-publish-job branch October 9, 2026 08:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants