Skip to content

Add a manually triggered snapshot publish - #3092

Merged
edgartwigg merged 1 commit into
mainfrom
feat/release-snapshot-job
Sep 18, 2026
Merged

edgartwigg merged 1 commit into
mainfrom
feat/release-snapshot-job

Conversation

@nedtwigg

Copy link
Copy Markdown
Member

Follow-up to #3089 and #3090.

#3090 removed snapshot publishing from main, which also removed the only way to exercise the
publishing credentials and the signing key without cutting a release. Releases are immutable on
Central, so "try it and see" is not available there.

This adds a release-snapshot workflow that publishes a snapshot, on workflow_dispatch only. A
push to any branch still cannot publish anything.

  • Runs in the maven-central environment, so the environment's branch policy decides where it can
    be dispatched from.
  • Refuses to run unless every published module's version ends in -SNAPSHOT, so it can never ship a
    release by accident.
  • Uses the new signing subkey 0xFA5C18CFB74EC7C6.

Note on where it can run. The environment currently allows only release, and that branch is
still at the pre-migration build, which has no publishToMavenCentral task. So dispatching there
will fail until a release happens — which is the thing this job is meant to de-risk. To use it
before the next release, main has to be added to the environment's branch policy. That is a
deliberate loosening, and it is worth being explicit about: what prevents a repeat of #3089 is that
nothing publishes automatically, nothing decodes a secret in CI, and the secrets are scoped to the
environment rather than the organization.

🤖 Generated with Claude Code

Removing snapshot publishing from main also removed the only way to
exercise the publishing credentials and the signing key without cutting a
release, which is immutable on Central.

This job publishes a snapshot on workflow_dispatch only, never on a push.
It runs in the maven-central environment, so the environment's branch
policy decides where it can be dispatched from, and it refuses to run if
any published module's version is not a -SNAPSHOT.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@edgartwigg
edgartwigg merged commit 324d98d into main Sep 18, 2026
31 checks passed
@edgartwigg
edgartwigg deleted the feat/release-snapshot-job branch September 18, 2026 00:24
@jbduncan

Copy link
Copy Markdown
Member

@nedtwigg Am I right to think that @edgartwigg is just another account of yours that was used for CODEOWNERS testing purposes in this case? :)

@nedtwigg

Copy link
Copy Markdown
Member Author

With Codeowners, it is not possible to self-approve, so you need at least one other account. I keep the logins in separate systems, so it does add a tiny bit of security.

@jbduncan

Copy link
Copy Markdown
Member

With Codeowners, it is not possible to self-approve, so you need at least one other account. I keep the logins in separate systems, so it does add a tiny bit of security.

That makes sense, thanks for confirming, my fears are assuaged. 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants