Repository navigation
固定发布工作流使用 Maven 3.9.16 - #4136
Conversation
Co-authored-by: binarywang <1343140+binarywang@users.noreply.github.com>
Co-authored-by: binarywang <1343140+binarywang@users.noreply.github.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 17f435e7c4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| @@ -0,0 +1,3 @@ | |||
| wrapperVersion=3.3.4 | |||
| distributionType=only-script | |||
| distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.16/apache-maven-3.9.16-bin.zip | |||
There was a problem hiding this comment.
当 Maven Wrapper 缓存未命中时,该 URL 对应的压缩包会被直接下载、解压并执行;由于未设置 distributionSha256Sum,新增脚本中的校验分支会被跳过。发布作业同时持有 Maven Central 凭据和已导入的 GPG 私钥,因此下载源或传输链路一旦返回被篡改的归档,就可能执行任意代码并窃取发布凭据或伪造制品;请在此处固定 Apache 官方公布的 SHA-256 值,使校验失败时终止发布。
AGENTS.md reference: AGENTS.md:L104-L106
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
🟡 Changes recommended
Maven 发行包缺少 SHA-256 完整性校验,会给持有发布凭据的工作流引入供应链风险。
1 open finding
What changed in this PR
该 PR 固定发布流程使用 Maven 3.9.16,避免新版 Resolver 生成不兼容的 staging bundle。
Changes:
- 新增 Maven Wrapper。
- 发布步骤改用
./mvnw。 - 固定 Maven 发行版本。
| File | Description |
|---|---|
mvnw |
新增 Wrapper 启动脚本 |
.mvn/wrapper/maven-wrapper.properties |
固定 Maven 3.9.16 |
.github/workflows/maven-publish.yml |
发布命令改用 Wrapper |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
🤖 Augment PR Summary摘要:为 Maven Central 发布流程固定 Maven 3.9.16。
🤖 Was this summary useful? React with 👍 or 👎 |
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

Maven Central 拒绝了发布工作流生成的 bundle。原因是 Runner 默认 Maven 3.10 的 Resolver 2 将仓库元数据写入 staging 目录。
./mvnw versions:set -DnewVersion=$VERSION ./mvnw clean deploy -P release