Skip to content

Migrate publishing to com.vanniktech.maven.publish - #3052

Open
Goooler wants to merge 1 commit into
mainfrom
g/20260911/migrate-maven-pub
Open

Migrate publishing to com.vanniktech.maven.publish#3052
Goooler wants to merge 1 commit into
mainfrom
g/20260911/migrate-maven-pub

Conversation

@Goooler

@Goooler Goooler commented Sep 11, 2026

Copy link
Copy Markdown
Member

No description provided.

@Goooler

Goooler commented Sep 11, 2026

Copy link
Copy Markdown
Member Author
Maven Local Diff Details

diff -rf /Users/goooler/Downloads/spotless-maven-local-before/com.diffplug.spotless.gradle.plugin/8.10.3-SNAPSHOT/com.diffplug.spotless.gradle.plugin-8.10.3-SNAPSHOT.pom /Users/goooler/Downloads/spotless-maven-local-after/com.diffplug.spotless.gradle.plugin/8.10.3-SNAPSHOT/com.diffplug.spotless.gradle.plugin-8.10.3-SNAPSHOT.pom
c8
  <name>spotless-plugin-gradle</name>
.
a9
  <url>https://github.com/diffplug/spotless</url>
  <licenses>
    <license>
      <name>The Apache Software License, Version 2.0</name>
      <url>https://www.apache.org/licenses/LICENSE-2.0.txt</url>
      <distribution>repo</distribution>
    </license>
  </licenses>
  <developers>
    <developer>
      <id>nedtwigg</id>
      <name>Ned Twigg</name>
      <email>ned.twigg@diffplug.com</email>
    </developer>
  </developers>
  <scm>
    <connection>scm:git:https://github.com/diffplug/spotless.git</connection>
    <developerConnection>scm:git:ssh:git@github.com/diffplug/spotless.git</developerConnection>
    <url>https://github.com/diffplug/spotless</url>
  </scm>
.
Only in /Users/goooler/Downloads/spotless-maven-local-after/com.diffplug.spotless.gradle.plugin/8.10.3-SNAPSHOT: com.diffplug.spotless.gradle.plugin-8.10.3-SNAPSHOT.pom.asc
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/com.diffplug.spotless.gradle.plugin/8.10.3-SNAPSHOT/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/com.diffplug.spotless.gradle.plugin/8.10.3-SNAPSHOT/maven-metadata-local.xml
c6
    <lastUpdated>20260911033037</lastUpdated>
.
c14
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <extension>pom.asc</extension>
        <value>8.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
.
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/com.diffplug.spotless.gradle.plugin/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/com.diffplug.spotless.gradle.plugin/maven-metadata-local.xml
c10
    <lastUpdated>20260911033037</lastUpdated>
.
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-lib/4.10.3-SNAPSHOT/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib/4.10.3-SNAPSHOT/maven-metadata-local.xml
c6
    <lastUpdated>20260911033037</lastUpdated>
.
c12
        <extension>module</extension>
.
c14
        <updated>20260911033037</updated>
.
c17
        <classifier>javadoc</classifier>
.
c20
        <updated>20260911033037</updated>
.
a22
        <extension>module.asc</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
.
a23
        <extension>jar.asc</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <classifier>sources</classifier>
.
c26
        <updated>20260911033037</updated>
.
a28
        <extension>pom</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <classifier>sources</classifier>
        <extension>jar.asc</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
.
c31
        <updated>20260911033037</updated>
.
c34
        <extension>pom.asc</extension>
.
c36
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <extension>jar.asc</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
.
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib/4.10.3-SNAPSHOT: spotless-lib-4.10.3-SNAPSHOT-javadoc.jar.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib/4.10.3-SNAPSHOT: spotless-lib-4.10.3-SNAPSHOT-sources.jar.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib/4.10.3-SNAPSHOT: spotless-lib-4.10.3-SNAPSHOT.jar.asc
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-lib/4.10.3-SNAPSHOT/spotless-lib-4.10.3-SNAPSHOT.module /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib/4.10.3-SNAPSHOT/spotless-lib-4.10.3-SNAPSHOT.module
d60 79
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib/4.10.3-SNAPSHOT: spotless-lib-4.10.3-SNAPSHOT.module.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib/4.10.3-SNAPSHOT: spotless-lib-4.10.3-SNAPSHOT.pom.asc
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-lib/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib/maven-metadata-local.xml
c10
    <lastUpdated>20260911033037</lastUpdated>
.
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-lib-extra/4.10.3-SNAPSHOT/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib-extra/4.10.3-SNAPSHOT/maven-metadata-local.xml
c6
    <lastUpdated>20260911033037</lastUpdated>
.
c12
        <classifier>javadoc</classifier>
        <extension>jar.asc</extension>
.
c14
        <updated>20260911033037</updated>
.
c17
        <extension>pom</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <extension>jar.asc</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <extension>module</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
.
c20
        <updated>20260911033037</updated>
.
a22
        <extension>module.asc</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
.
c24
        <extension>jar.asc</extension>
.
c26
        <updated>20260911033037</updated>
.
c29
        <extension>pom.asc</extension>
.
c31
        <updated>20260911033037</updated>
.
c34
        <classifier>sources</classifier>
        <extension>jar</extension>
.
c36
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <classifier>javadoc</classifier>
        <extension>jar</extension>
        <value>4.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
.
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib-extra/4.10.3-SNAPSHOT: spotless-lib-extra-4.10.3-SNAPSHOT-javadoc.jar.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib-extra/4.10.3-SNAPSHOT: spotless-lib-extra-4.10.3-SNAPSHOT-sources.jar.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib-extra/4.10.3-SNAPSHOT: spotless-lib-extra-4.10.3-SNAPSHOT.jar.asc
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-lib-extra/4.10.3-SNAPSHOT/spotless-lib-extra-4.10.3-SNAPSHOT.module /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib-extra/4.10.3-SNAPSHOT/spotless-lib-extra-4.10.3-SNAPSHOT.module
d120 139
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib-extra/4.10.3-SNAPSHOT: spotless-lib-extra-4.10.3-SNAPSHOT.module.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib-extra/4.10.3-SNAPSHOT: spotless-lib-extra-4.10.3-SNAPSHOT.pom.asc
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-lib-extra/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/spotless-lib-extra/maven-metadata-local.xml
c10
    <lastUpdated>20260911033037</lastUpdated>
.
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-maven-plugin/3.10.3-SNAPSHOT/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/spotless-maven-plugin/3.10.3-SNAPSHOT/maven-metadata-local.xml
c6
    <lastUpdated>20260911033037</lastUpdated>
.
c13
        <extension>jar.asc</extension>
.
c15
        <updated>20260911033037</updated>
.
c18
        <extension>pom</extension>
        <value>3.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <extension>module.asc</extension>
        <value>3.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
.
c21
        <updated>20260911033037</updated>
.
a23
        <extension>pom.asc</extension>
        <value>3.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
.
c26
        <updated>20260911033037</updated>
.
c29
        <classifier>sources</classifier>
        <extension>jar</extension>
.
c31
        <updated>20260911033037</updated>
.
a33
        <classifier>javadoc</classifier>
        <extension>jar.asc</extension>
        <value>3.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <extension>jar.asc</extension>
        <value>3.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <classifier>javadoc</classifier>
.
c36
        <updated>20260911033037</updated>
.
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-maven-plugin/3.10.3-SNAPSHOT: spotless-maven-plugin-3.10.3-SNAPSHOT-javadoc.jar.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-maven-plugin/3.10.3-SNAPSHOT: spotless-maven-plugin-3.10.3-SNAPSHOT-sources.jar.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-maven-plugin/3.10.3-SNAPSHOT: spotless-maven-plugin-3.10.3-SNAPSHOT.jar.asc
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-maven-plugin/3.10.3-SNAPSHOT/spotless-maven-plugin-3.10.3-SNAPSHOT.module /Users/goooler/Downloads/spotless-maven-local-after/spotless-maven-plugin/3.10.3-SNAPSHOT/spotless-maven-plugin-3.10.3-SNAPSHOT.module
d125 144
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-maven-plugin/3.10.3-SNAPSHOT: spotless-maven-plugin-3.10.3-SNAPSHOT.module.asc
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-maven-plugin/3.10.3-SNAPSHOT/spotless-maven-plugin-3.10.3-SNAPSHOT.pom /Users/goooler/Downloads/spotless-maven-local-after/spotless-maven-plugin/3.10.3-SNAPSHOT/spotless-maven-plugin-3.10.3-SNAPSHOT.pom
c12
  <name>Spotless Maven Plugin</name>
.
d24 28
a31
    </developer>
    <developer>
      <id>lutovich</id>
      <name>Konstantin Lutovich</name>
      <email>konstantin.lutovich@neotechnology.com</email>
.
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-maven-plugin/3.10.3-SNAPSHOT: spotless-maven-plugin-3.10.3-SNAPSHOT.pom.asc
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-maven-plugin/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/spotless-maven-plugin/maven-metadata-local.xml
c10
    <lastUpdated>20260911033037</lastUpdated>
.
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-plugin-gradle/8.10.3-SNAPSHOT/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/spotless-plugin-gradle/8.10.3-SNAPSHOT/maven-metadata-local.xml
c6
    <lastUpdated>20260911033037</lastUpdated>
.
a11
        <classifier>sources</classifier>
.
c14
        <updated>20260911033037</updated>
.
a16
        <extension>module</extension>
        <value>8.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <extension>pom.asc</extension>
        <value>8.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <classifier>javadoc</classifier>
        <extension>jar.asc</extension>
        <value>8.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
        <extension>module.asc</extension>
        <value>8.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
.
c18
        <extension>jar.asc</extension>
.
c20
        <updated>20260911033037</updated>
.
c23
        <extension>jar.asc</extension>
.
c25
        <updated>20260911033037</updated>
.
a27
        <extension>jar</extension>
        <value>8.10.3-SNAPSHOT</value>
        <updated>20260911033037</updated>
      </snapshotVersion>
      <snapshotVersion>
.
c30
        <updated>20260911033037</updated>
.
c36
        <updated>20260911033037</updated>
.
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-plugin-gradle/8.10.3-SNAPSHOT: spotless-plugin-gradle-8.10.3-SNAPSHOT-javadoc.jar.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-plugin-gradle/8.10.3-SNAPSHOT: spotless-plugin-gradle-8.10.3-SNAPSHOT-sources.jar.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-plugin-gradle/8.10.3-SNAPSHOT: spotless-plugin-gradle-8.10.3-SNAPSHOT.jar.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-plugin-gradle/8.10.3-SNAPSHOT: spotless-plugin-gradle-8.10.3-SNAPSHOT.module.asc
Only in /Users/goooler/Downloads/spotless-maven-local-after/spotless-plugin-gradle/8.10.3-SNAPSHOT: spotless-plugin-gradle-8.10.3-SNAPSHOT.pom.asc
diff -rf /Users/goooler/Downloads/spotless-maven-local-before/spotless-plugin-gradle/maven-metadata-local.xml /Users/goooler/Downloads/spotless-maven-local-after/spotless-plugin-gradle/maven-metadata-local.xml
c10
    <lastUpdated>20260911033037</lastUpdated>
.

Comment on lines +37 to +40
if (System.getenv("JITPACK") == "true") {
signing {
isRequired = false
}

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we still publish to Jitpack? I'd prefer removing it.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved publishing compilation, signing, Javadoc, and metadata issues block approval.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This pull request migrates publishing from Nexus to com.vanniktech.maven.publish, centralizing Maven Central metadata and updating CI validation.

Changes:

  • Replaces Nexus publishing with Vanniktech publishing and signing.
  • Moves coordinates and POM metadata into shared properties.
  • Updates build logic, documentation, dependencies, and CI checks.
File summaries
File Reviewed change / final review note
testlib/gradle.properties Adds publishing metadata.
testlib/build.gradle.kts Removes legacy artifact configuration.
settings.gradle.kts Maps Central credentials.
plugin-maven/README.md Updates publishing links.
plugin-maven/gradle.properties Defines Maven plugin metadata.
plugin-maven/build.gradle.kts Configures Maven plugin publishing.
plugin-gradle/gradle.properties Defines Gradle plugin metadata.
plugin-gradle/build.gradle.kts Updates plugin metadata; legacy declaration still loses its description (moderate, 1 vote).
lib/gradle.properties Defines library metadata.
lib/build.gradle.kts Removes legacy artifact configuration.
lib-extra/gradle.properties Defines extra library metadata.
lib-extra/build.gradle.kts Removes legacy artifact configuration.
gradle/libs.versions.toml Replaces the Nexus plugin dependency.
gradle.properties Adds shared Maven Central/POM settings; legacy marker metadata remains incomplete (moderate, 2 votes).
build.gradle.kts Removes the Nexus publishing plugin.
build-logic/src/main/kotlin/spotless.nexus-publish.gradle.kts Removes obsolete Nexus configuration.
build-logic/src/main/kotlin/spotless.java-setup.gradle.kts Applies the shared group ID.
build-logic/src/main/kotlin/spotless.java-publish.gradle.kts Adds Vanniktech publishing/signing; unresolved decode64 reference (critical, 1 vote), snapshot signing failure risk (critical, 3 votes), and lost Javadoc verification dependency (moderate, 3 votes).
build-logic/build.gradle.kts Updates build-logic dependencies.
.github/workflows/ci.yml Adds local publication validation.
Review details

Suppressed comments (1)

plugin-gradle/build.gradle.kts:61

  • The new metadata migration updates only the primary Gradle plugin declaration, but the legacy declaration below still uses project.description (line 86). Since the old description property was removed from gradle.properties, the legacy plugin marker will lose its description and publish incomplete plugin metadata; use POM_DESCRIPTION for that declaration too or retain the old property.
      description = property("POM_DESCRIPTION").toString()
  • Files reviewed: 19/20 changed files
  • Comments generated: 4
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +37 to +45
if (System.getenv("JITPACK") == "true") {
signing {
isRequired = false
}
} else {
signing {
if (
!project.providers.gradleProperty("signingInMemoryKey").isPresent &&
System.getenv("ORG_GRADLE_PROJECT_gpg_key64") != null

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I recall we don't publish SNAPSHOTs for now. We don't have to check the siging.

Comment on lines +47 to +51
val gpgKey = decode64("ORG_GRADLE_PROJECT_gpg_key64")
useInMemoryPgpKeys(
"0x4272C851",
gpgKey,
System.getenv("ORG_GRADLE_PROJECT_gpg_passphrase"),

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems we can't do that in build-logic...

plugins {
`java-library`
`maven-publish`
id("com.vanniktech.maven.publish")

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified javadoc on CI by publishToMavenLocal.

Comment thread gradle.properties
# naming convention '-maven-plugin' allows mvn 'spotless:check' instead of 'spotless-plugin-maven:check'
artifactIdMaven=spotless-maven-plugin
GROUP=com.diffplug.spotless
POM_DESCRIPTION=Spotless - keep your code spotless with Gradle

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

POM_DESCRIPTION is good. We can default project description to that if necessary.

@nedtwigg

Copy link
Copy Markdown
Member

to my knowledge we've had no issues with io.github.gradle-nexus.publish-plugin. What's the value we get by switching?

@Goooler

Goooler commented Sep 12, 2026

Copy link
Copy Markdown
Member Author

io.github.gradle-nexus.publish-plugin is no longer actively maintained. In contrast, gradle-maven-publish-plugin is actively maintained, quickly adapts to new Maven Central requirements (e.g., v0.37.0), and out-of-the-box fixes issues like gradle-nexus/publish-plugin#307 (publishing plugin marker artifacts to Maven Central so snapshot/release versions can be resolved via plugins { id(...) }).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants