Publish pipeline: goreleaser + Maven Central + npm (#1)

* feat(cli): add Version var and version subcommand

* build(gradle): introduce uatu.version property for lockstep releases

* build(sdk-android): swap GitHub Packages for vanniktech Maven Central plugin

* build(spec-api): make package publish-ready for npm

* ci(release): add goreleaser config for cross-platform uatu CLI builds

* ci: add ci and release GitHub Actions workflows

* ci: restrict ci.yml to PR + workflow_dispatch (no direct push to master)

* docs(release): add local release targets, env example, and install docs

* build(sdk-android): make signAllPublications conditional on signing key

* ci(release): stage sidecar JAR at embed path before go build

* chore(spec-api): regenerate package-lock for updated package.json

* ci: install protoc-gen-go plugins before buf generate

* ci: bump Node to 22 (required for --experimental-strip-types)
This commit is contained in:
pj authored and GitHub committed 2026-04-18 08:50:57 +07:00
1 parent 6e4c832678
commit 0570719e6f
17 files changed
+556 -37

No files matched your search

+29
View File
@@ -0,0 +1,29 @@
# uatu release credentials (local dev only).
#
# Copy to `.env.local` (gitignored) and fill in values ONLY if you need to
# fire a real release from your laptop. Day-to-day work and the `release-cli`
# / `release-android-local` / `release-npm-dry` Make targets don't need any
# of these — they're snapshot/local-only.
#
# In CI, these are provided via GitHub Actions secrets (see .github/workflows/release.yml).
# npm automation token (bypasses 2FA).
# Create at npmjs.com → Access Tokens → Generate New Token → Automation.
NPM_TOKEN=
# Sonatype Central user token (username half).
# Create at central.sonatype.com → Account → Generate User Token.
ORG_GRADLE_PROJECT_mavenCentralUsername=
# Sonatype Central user token (password half).
ORG_GRADLE_PROJECT_mavenCentralPassword=
# ASCII-armored GPG private key for release signing. Include the full
# "-----BEGIN PGP PRIVATE KEY BLOCK-----…-----END PGP PRIVATE KEY BLOCK-----"
# payload, with literal \n newlines escaped inside quotes, e.g.:
# ORG_GRADLE_PROJECT_signingInMemoryKey="-----BEGIN PGP PRIVATE KEY BLOCK-----\nlQVYBG…\n-----END PGP PRIVATE KEY BLOCK-----"
# Generate with: gpg --export-secret-keys --armor <KEYID>
ORG_GRADLE_PROJECT_signingInMemoryKey=
# Passphrase for the GPG key above.
ORG_GRADLE_PROJECT_signingInMemoryKeyPassword=