← All tasks
javagoogle/gson #2892Not a task: already works

Migrate from OSSRH to Central

envgap__google__gson-2892

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
69cb755e5209b719b57f3b6f1a864b080cdca314
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

google/gson #2892 · read the original issue
See https://central.sonatype.org/pages/ossrh-eol/ and https://central.sonatype.org/publish/publish-portal-maven/.

I had told @eamonnmcmanus that I would make an attempt at this, but I am emerging defeated... :)

The source-code changes for most of our own migrations have looked like https://github.com/google/truth/pull/1544. I started working on a similar change to GSON, removing `<distributionManagement>`, removing `maven-deploy-plugin` from `dependencyManagement`, and adding `central-publishing-maven-plugin` to `dependencyManagement` with `<skipPublishing>${gson.isInternalModule}</skipPublishing>` inside the `configuration` section. I also tried listing `central-publishing-maven-plugin` inside the `release` profile.

On top of that, we had to create a new user token, following the instructions at https://central.sonatype.org/publish/generate-portal-token/, and plug it into `~/.m2/settings.xml`. (I've been using `<id>central</id>`, but I'm not sure if that exact name is significant.)

Anyway, I was working through the quite detailed instructions at https://github.com/google/gson/blob/main/ReleaseProcess.md (even knowing that I wouldn't ultimately have the permissions to deploy), and I got the impression that `maven-release-plugin` (which I hadn't used before) is running `maven-deploy-plugin` whether we want it to or not.

It is _probably_ possible to continue using `maven-deploy-plugin` (instead of migrating to `central-publishing-maven-plugin`) by switching to the legacy shim API documented at https://central.sonatype.org/publish/publish-portal-ossrh-staging-api/. However, I and others have had trouble with missing files in our resulting deployments. (Supposedly that is an issue only if you upload different files from different IPs, but that seems highly unlikely in the cases I'm aware of. I think I may at least have heard that there were some potential fixes to remaining issues.) But as a more general point, it's a legacy shim.

The right thing to do is probably to either migrate off `maven-release-plugin` (at least for the actual deployment) or to find a way to force it to use `central-publishing-maven-plugin` instead of `maven-deploy-plugin` (if possible).
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]