# sanderling release credentials (local dev only). # # Copy to `.env.local` (gitignored) and fill in values ONLY if you need to # fire a real release from your laptop. Day-to-day work and the `release-cli` # / `release-android-local` / `release-npm-dry` Make targets don't need any # of these. They're snapshot/local-only. # # In CI, these are provided via GitHub Actions secrets (see .github/workflows/release.yml). # npm automation token (bypasses 2FA). # Create at npmjs.com → Access Tokens → Generate New Token → Automation. NPM_TOKEN= # Sonatype Central user token (username half). # Create at central.sonatype.com → Account → Generate User Token. ORG_GRADLE_PROJECT_mavenCentralUsername= # Sonatype Central user token (password half). ORG_GRADLE_PROJECT_mavenCentralPassword= # ASCII-armored GPG private key for release signing. Include the full # "-----BEGIN PGP PRIVATE KEY BLOCK-----…-----END PGP PRIVATE KEY BLOCK-----" # payload, with literal \n newlines escaped inside quotes, e.g.: # ORG_GRADLE_PROJECT_signingInMemoryKey="-----BEGIN PGP PRIVATE KEY BLOCK-----\nlQVYBG…\n-----END PGP PRIVATE KEY BLOCK-----" # Generate with: gpg --export-secret-keys --armor ORG_GRADLE_PROJECT_signingInMemoryKey= # Passphrase for the GPG key above. ORG_GRADLE_PROJECT_signingInMemoryKeyPassword=