Skip to content

chore: Maintenance (#1447) #158

chore: Maintenance (#1447)

chore: Maintenance (#1447) #158

Workflow file for this run

# This workflow will build a Java project with Gradle
# For more information see: https://help.github.com/actions/language-and-framework-guides/building-and-testing-java-with-gradle
name: JavaCI
on:
push:
branches: [main]
paths-ignore:
- "README.md"
- "**/README.md"
- "CODE_OF_CONDUCT.md"
- "CONTRIBUTING.md"
- "pull_request_template.md"
- ".lift/.toml"
- "**/.lift/.toml"
- "SECURITY.md"
- "LICENSE"
- ".github/ISSUE_TEMPLATE/**"
- ".github/assets/**"
- ".github/workflows/**"
- ".github/pr-labeler.yml"
- "renovate.json"
- ".whitesource"
- "gradle/libs.versions.toml"
- "gradle/verification-metadata.xml"
- "gradle/verification-metadata-clean.xml"
- "lowkey-vault-docker/src/docker/Dockerfile"
- "gradle/wrapper/gradle-wrapper.properties"
- "gradle/wrapper/gradle-wrapper.jar"
- "gradlew"
- "gradlew.bat"
- "config/ossindex/exclusions.txt"
- ".idea/**"
- ".gitignore"
- ".qlty/**"
permissions: read-all
jobs:
build:
runs-on: ubuntu-latest
steps:
# Set up build environment
- name: Checkout
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
fetch-depth: 0
token: ${{ secrets.PUBLISH_KEY }}
- name: Set up JDK 17
uses: actions/setup-java@3a4f6e1af504cf6a31855fa899c6aa5355ba6c12 # v4.7.0
with:
distribution: temurin
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@06832c7b30a0129d7fb559bcc6e43d26f6374244 # v4.3.1
with:
gradle-home-cache-cleanup: true
- name: Build with Gradle
run: ./gradlew tagVersion build -PgithubUser=${{ secrets.PUBLISH_USER_NAME }} -PgithubToken=${{ secrets.PUBLISH_KEY }}
- name: Decode key
run: |
mkdir -p ${{ runner.temp }}/.gnupg/
echo -e "${{ secrets.OSSRH_GPG_SECRET_KEY }}" | base64 --decode > ${{ runner.temp }}/.gnupg/secring.gpg
- name: Docker Login
uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3.4.0
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Build with Gradle
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
run: >
./gradlew publish publishToSonatype sonar closeAndReleaseSonatypeStagingRepository
-x test -x dockerBuild -x dockerRun -x dockerStop
-PgithubUser=${{ secrets.PUBLISH_USER_NAME }}
-PgithubToken=${{ secrets.PUBLISH_KEY }}
-PossrhUsername=${{ secrets.OSSRH_USER }}
-PossrhPassword=${{ secrets.OSSRH_PASS }}
-Psigning.keyId=${{ secrets.SIGNING_KEY_ID }}
-Psigning.password=${{ secrets.OSSRH_GPG_SECRET_KEY_PASSWORD }}
-Psigning.secretKeyRingFile=${{ runner.temp }}/.gnupg/secring.gpg
- name: Clean-up GPG key
if: always()
run: |
rm -rf ${{ runner.temp }}/.gnupg/