Compare commits

..
Author SHA1 Message Date
dependabot[bot] 0624d65fe1 Bump the github-actions group across 1 directory with 3 updates
Bumps the github-actions group with 3 updates in the / directory: [Alfresco/alfresco-build-tools](https://github.com/alfresco/alfresco-build-tools), [actions/checkout](https://github.com/actions/checkout) and [docker/login-action](https://github.com/docker/login-action).


Updates `Alfresco/alfresco-build-tools` from 15.7.1 to 18.15.0
- [Release notes](https://github.com/alfresco/alfresco-build-tools/releases)
- [Commits](https://github.com/alfresco/alfresco-build-tools/compare/v15.7.1...v18.15.0)

Updates `actions/checkout` from 4.2.2 to 7.0.0
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4.2.2...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)

Updates `docker/login-action` from 3.7.0 to 4.2.0
- [Release notes](https://github.com/docker/login-action/releases)
- [Commits](https://github.com/docker/login-action/compare/c94ce9fb468520275223c153574b00df6fe4bcc9...650006c6eb7dba73a995cc03b0b2d7f5ca915bee)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: Alfresco/alfresco-build-tools
  dependency-version: 17.7.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
- dependency-name: docker/login-action
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 17:08:23 +00:00
12 changed files with 39 additions and 274 deletions
-7
View File
@@ -1,7 +0,0 @@
env:
global:
# Both variables are required to be set before the release process starts.
# As the release is triggered by a commit message with "[release]" keyword,
# setting these variables to new values can be done in the same commit and will indicate the release and the dev versions in it.
- RELEASE_VERSION=4.17.0-A2
- DEVELOPMENT_VERSION=4.17.0-A3-SNAPSHOT
+18 -84
View File
@@ -13,9 +13,6 @@ on:
- feature/**
workflow_dispatch:
permissions:
contents: read
env:
JAVA_VERSION: '21'
MAVEN_USERNAME: ${{ secrets.NEXUS_USERNAME }}
@@ -23,13 +20,12 @@ env:
MAVEN_CENTRAL_USERNAME: ${{ secrets.OSS_SONATYPE_USERNAME }}
MAVEN_CENTRAL_PASSWORD: ${{ secrets.OSS_SONATYPE_PASSWORD }}
GITHUB_ACTIONS_DEPLOY_TIMEOUT: 90
# Note: RELEASE_VERSION and DEVELOPMENT_VERSION are loaded from .github/release-versions.yml
jobs:
pre_commit:
runs-on: ubuntu-latest
steps:
- uses: Alfresco/alfresco-build-tools/.github/actions/pre-commit@v15.7.1
- uses: Alfresco/alfresco-build-tools/.github/actions/pre-commit@v18.15.0
build:
name: "Build application"
@@ -40,8 +36,8 @@ jobs:
MAVEN_CLI_OPTS: >
-B -q -e -fae -V -DinstallAtEnd=true -U
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: Alfresco/alfresco-build-tools/.github/actions/setup-java-build@v15.7.1
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: Alfresco/alfresco-build-tools/.github/actions/setup-java-build@v18.15.0
with:
java-version: ${{ env.JAVA_VERSION }}
- name: "Build"
@@ -68,9 +64,6 @@ jobs:
- name: "26.1 Community Java 21"
java-version: 21
suite: -Pcommunity-261-tests
- name: "25.5 Enterprise Java 17"
java-version: 17
suite: -Penterprise-255-tests
- name: "25.4 Enterprise Java 17"
java-version: 17
suite: -Penterprise-254-tests
@@ -126,18 +119,18 @@ jobs:
java-version: 11
suite: -Pcommunity-74-tests
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: Alfresco/alfresco-build-tools/.github/actions/get-build-info@v15.7.1
- uses: Alfresco/alfresco-build-tools/.github/actions/setup-java-build@v15.7.1
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: Alfresco/alfresco-build-tools/.github/actions/get-build-info@v18.15.0
- uses: Alfresco/alfresco-build-tools/.github/actions/setup-java-build@v18.15.0
with:
java-version: ${{ matrix.java-version }}
- name: "Login to Docker Hub"
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: "Login to Quay.io"
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0
with:
registry: quay.io
username: ${{ secrets.QUAY_USERNAME }}
@@ -145,71 +138,18 @@ jobs:
- name: "Build"
run: mvn clean install -B ${{ matrix.suite }}
release:
name: "Release"
runs-on: ubuntu-latest
permissions:
contents: write
needs: [tests]
outputs:
release_tag: ${{ steps.release_meta.outputs.release_tag }}
env:
MAVEN_USERNAME: ${{ secrets.NEXUS_USERNAME }}
MAVEN_PASSWORD: ${{ secrets.NEXUS_PASSWORD }}
if: >
needs.tests.result == 'success' &&
(github.ref_name == 'master' || startsWith(github.ref_name, 'fix/') || startsWith(github.ref_name, 'feature/')) &&
!contains(github.event.head_commit.message, '[no release]') &&
github.event_name != 'pull_request' &&
contains(github.event.head_commit.message, '[release]')
steps:
- name: "Generate GitHub App token"
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ vars.GH_APP_ENGINEERING_CONTRIB_CLIENT_ID }}
private-key: ${{ secrets.GH_APP_ENGINEERING_CONTRIB_PRIVATE_KEY }}
permission-contents: write
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
token: ${{ steps.app-token.outputs.token }}
fetch-depth: 0
- uses: Alfresco/alfresco-build-tools/.github/actions/env-load-from-yaml@v18.21.2
with:
yml_path: .github/release-versions.yml
- name: "Export release metadata"
id: release_meta
run: echo "release_tag=${RELEASE_VERSION}" >> "$GITHUB_OUTPUT"
- uses: Alfresco/alfresco-build-tools/.github/actions/get-build-info@v18.21.2
- uses: Alfresco/alfresco-build-tools/.github/actions/free-hosted-runner-disk-space@v18.21.2
- uses: Alfresco/alfresco-build-tools/.github/actions/setup-java-build@v18.21.2
with:
java-version: ${{ env.JAVA_VERSION }}
- uses: Alfresco/alfresco-build-tools/.github/actions/maven-release-slim@v18.21.2
with:
token: ${{ steps.app-token.outputs.token }}
release-version: ${{ env.RELEASE_VERSION }}
development-version: ${{ env.DEVELOPMENT_VERSION }}
maven-args: >
-DskipTests
-DbuildNumber=${{ github.run_number }}
check_version:
name: "Check version"
runs-on: ubuntu-latest
needs: [tests, release]
needs: [tests]
if: >
needs.tests.result == 'success' &&
contains(github.event.head_commit.message, '[publish]') &&
(needs.release.result == 'success' || needs.release.result == 'skipped')
contains(github.event.head_commit.message, '[publish]')
outputs:
is_ga: ${{ steps.publish_version.outputs.is_ga }}
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
ref: ${{ needs.release.outputs.release_tag || github.ref }}
- uses: Alfresco/alfresco-build-tools/.github/actions/get-build-info@v15.7.1
- uses: Alfresco/alfresco-build-tools/.github/actions/setup-java-build@v15.7.1
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: Alfresco/alfresco-build-tools/.github/actions/get-build-info@v18.15.0
- uses: Alfresco/alfresco-build-tools/.github/actions/setup-java-build@v18.15.0
with:
java-version: ${{ env.JAVA_VERSION }}
- name: "Check version"
@@ -227,21 +167,15 @@ jobs:
publish:
name: "Publish artifacts"
runs-on: ubuntu-latest
needs: [tests, check_version, release]
needs: [tests, check_version]
if: >
needs.tests.result == 'success' &&
contains(github.event.head_commit.message, '[publish]') &&
needs.check_version.result == 'success' &&
needs.check_version.outputs.is_ga == 'true' &&
(needs.release.result == 'success' || needs.release.result == 'skipped')
contains(github.event.head_commit.message, '[publish]') && needs.check_version.outputs.is_ga == 'true'
env:
GPG_SIGNING_PASSPHRASE: ${{ secrets.GPG_SIGNING_PASSPHRASE }}
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
ref: ${{ needs.release.outputs.release_tag || github.ref }}
- uses: Alfresco/alfresco-build-tools/.github/actions/get-build-info@v15.7.1
- uses: Alfresco/alfresco-build-tools/.github/actions/setup-java-build@v15.7.1
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: Alfresco/alfresco-build-tools/.github/actions/get-build-info@v18.15.0
- uses: Alfresco/alfresco-build-tools/.github/actions/setup-java-build@v18.15.0
with:
java-version: ${{ env.JAVA_VERSION }}
- name: "Build"
+2 -2
View File
@@ -16,8 +16,8 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- uses: Alfresco/alfresco-build-tools/.github/actions/maven-dependency-scan@v17.0.0
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: Alfresco/alfresco-build-tools/.github/actions/maven-dependency-scan@v18.15.0
with:
java-version: '21'
maven-version: '3.9.9'
+12 -2
View File
@@ -177,6 +177,16 @@ To test new unreleased (unsupported) features, you can use the following snippet
## For Developers that want to contribute to the SDK
See the [Developers Wiki page](https://github.com/Alfresco/alfresco-sdk/wiki/Developer-Wiki).
## Releasing the SDK
## Publishing the release on Maven Central
- Manually change the version from SNAPSHOT to final (eg. when releasing SDK 4.16.0, replacing all the occurrences of 4.16.0-SNAPSHOT with 4.16.0)
See [docs/release-process.md](docs/release-process.md) for the current automated release process (Nexus, verified commits, tags, and Maven Central publishing).
- Commit and push changes to GitHub with the commit message [publish], then it will automatically publish your artifacts to maven central
- Only GA versions is published to maven central, there is a check in the CI pipeline (called "check_version") to check if the version is non-GA or not, and if it's not, it will skip the "publish" step. Therefore, only "number.number.number" versions will be published to maven central, and any version with a suffix (eg. -Ax, -SNAPSHOT, -RC1, -beta-1) will not be published to maven central.
At this point, we need to manually proceed with the remaining steps:
1- Manually create a release tag on GitHub
2- Manually change the version from final to next SNAPSHOT (eg. replacing all the occurrences of 4.16.0-SNAPSHOT with 4.17.0 (in pom.xml, not in READMEs - if not needed)
3- Commit and push on GitHub
@@ -11,7 +11,7 @@
<parent>
<groupId>org.alfresco.maven</groupId>
<artifactId>alfresco-sdk-aggregator</artifactId>
<version>4.17.0-A3-SNAPSHOT</version>
<version>4.17.0-A1</version>
<relativePath>../../pom.xml</relativePath>
</parent>
@@ -12,7 +12,7 @@
<parent>
<groupId>org.alfresco.maven</groupId>
<artifactId>alfresco-sdk-aggregator</artifactId>
<version>4.17.0-A3-SNAPSHOT</version>
<version>4.17.0-A1</version>
<relativePath>../../pom.xml</relativePath>
</parent>
@@ -14,7 +14,7 @@
<parent>
<groupId>org.alfresco.maven</groupId>
<artifactId>alfresco-sdk-aggregator</artifactId>
<version>4.17.0-A3-SNAPSHOT</version>
<version>4.17.0-A1</version>
<relativePath>../../pom.xml</relativePath>
</parent>
+1 -1
View File
@@ -17,7 +17,7 @@
<parent>
<groupId>org.alfresco.maven</groupId>
<artifactId>alfresco-sdk-aggregator</artifactId>
<version>4.17.0-A3-SNAPSHOT</version>
<version>4.17.0-A1</version>
<relativePath>../../pom.xml</relativePath>
</parent>
-158
View File
@@ -1,158 +0,0 @@
# Alfresco SDK release process
This document describes how to release the Alfresco SDK using the automated CI pipeline introduced in [ACS-12085](https://hyland.atlassian.net/browse/ACS-12085).
Releases are performed on **`master`** via GitHub Actions. The pipeline uses [`maven-release-slim`](https://github.com/Alfresco/alfresco-build-tools) from Alfresco build-tools and a GitHub App installation token to create **verified** commits and tags.
## Version conventions
### Alpha versions (dot notation)
Alpha releases **must** use a dot between `A` and the alpha number:
| Correct | Incorrect |
|---------|-----------|
| `4.17.0-A.1` | `4.17.0-A1` |
| `4.17.0-A.2` | `4.17.0-A2` |
Use this format in `RELEASE_VERSION`, Git tags, and Maven coordinates for all new alpha releases.
### Next development version (`-SNAPSHOT`)
`DEVELOPMENT_VERSION` **must** include the `-SNAPSHOT` suffix. This is the version written to all POMs after the release completes.
| Correct | Incorrect |
|---------|-----------|
| `4.17.0-A.3-SNAPSHOT` | `4.17.0-A.3` |
| `4.18.0-SNAPSHOT` | `4.18.0` |
This applies to both alpha and GA release cycles.
## Overview
| Step | Trigger | CI job | Result |
|------|---------|--------|--------|
| Alpha / Nexus release | `[release]` in commit message | `release` | Deploy to Alfresco Nexus, Git tag, verified bot commits |
| GA Maven Central publish | `[publish]` in commit message | `publish` | Publish to Maven Central (GA versions only) |
Alpha releases (for example `4.17.0-A.2`) are deployed to **Nexus only**. GA releases (for example `4.17.0`) can additionally be published to **Maven Central** using `[publish]`.
## Prerequisites
- Merge your changes to **`master`** (or use a PR merged to `master`).
- Ensure CI tests pass. Do not use `[skip tests]` on a release commit.
- Confirm the repository has the `GH_APP_ENGINEERING_CONTRIB_CLIENT_ID` variable and `GH_APP_ENGINEERING_CONTRIB_PRIVATE_KEY` secret configured (DevOps).
- Protected branches must allow verified commits from the engineering-contrib GitHub App.
## Configure release versions
Version numbers are **not** stored in `.github/workflows/ci.yml`. They live in [`.github/release-versions.yml`](../.github/release-versions.yml):
```yaml
env:
global:
- RELEASE_VERSION=4.17.0-A.2
- DEVELOPMENT_VERSION=4.17.0-A.3-SNAPSHOT
```
| Variable | Purpose | Example (alpha) | Example (GA) |
|----------|---------|-----------------|--------------|
| `RELEASE_VERSION` | Version to release and tag | `4.17.0-A.2` | `4.17.0` |
| `DEVELOPMENT_VERSION` | Next development version written to POMs after release (must end with `-SNAPSHOT`) | `4.17.0-A.3-SNAPSHOT` | `4.18.0-SNAPSHOT` |
Update both values in the **same commit** that triggers the release. The GitHub App bot does **not** modify this file; you must update it again before the next release.
> **Note:** Release versions are kept in `.github/release-versions.yml` (not in workflow files) so the GitHub App token does not require `workflows: write` permission.
## Alpha release (Nexus)
Example: release `4.17.0-A.3` when `master` is on `4.17.0-A.3-SNAPSHOT`.
1. Update [`.github/release-versions.yml`](../.github/release-versions.yml):
```yaml
- RELEASE_VERSION=4.17.0-A.3
- DEVELOPMENT_VERSION=4.17.0-A.4-SNAPSHOT
```
2. Commit and push to **`master`** with `[release]` in the commit message, for example:
```text
[release] Alfresco SDK 4.17.0-A.3 alpha
```
3. Wait for the CI workflow to finish. The `release` job runs only when:
- Tests succeed
- The branch is `master`, `fix/**`, or `feature/**`
- The commit message contains `[release]`
- The commit message does **not** contain `[no release]`
### What happens automatically
When the `release` job succeeds, CI will:
1. Set all POM versions to `RELEASE_VERSION`
2. Deploy artifacts to Alfresco Nexus
3. Create a **verified** bot commit for the release version
4. Create a Git tag named exactly `RELEASE_VERSION` (for example `4.17.0-A.3`)
5. Set all POM versions to `DEVELOPMENT_VERSION`
6. Create a **verified** bot commit for the next development version
You should **not** manually create Git tags or manually bump POM versions for the release and post-release commits; the pipeline handles that.
### After an alpha release
On `master` you should see:
- Git tag: `4.17.0-A.3` (plain version string from `RELEASE_VERSION`)
- Two new **Verified** commits from the engineering-contrib bot
- Root POM version: `4.17.0-A.4-SNAPSHOT`
- Artifacts on Alfresco Nexus for `4.17.0-A.3`
## GA release and Maven Central
For a GA release (version matching `major.minor.patch` with no suffix):
1. Update [`.github/release-versions.yml`](../.github/release-versions.yml), for example:
```yaml
- RELEASE_VERSION=4.17.0
- DEVELOPMENT_VERSION=4.18.0-SNAPSHOT
```
2. Push to **`master`** with both keywords in the **same** commit message:
```text
[release][publish] Alfresco SDK 4.17.0
```
To publish to Maven Central as part of the GA release, include `[publish]` in the **same** commit message as `[release]` so the workflow can publish the tagged `RELEASE_VERSION`.
A standalone `[publish]` commit (without `[release]`) will publish only if the POM version on that commit is already GA. After a release run, `master` is typically bumped to `DEVELOPMENT_VERSION` (`-SNAPSHOT`), so a later `[publish]` commit will be skipped by `check_version`.
The `check_version` job verifies the version matches `^\d+\.\d+\.\d+$` before Maven Central publish runs. Alpha, SNAPSHOT, RC, and other suffixed versions are skipped.
## Commit message keywords
| Keyword | Effect |
|---------|--------|
| `[release]` | Run the automated Nexus release |
| `[publish]` | Attempt Maven Central publish (GA only) |
| `[no release]` | Skip the release job even if `[release]` would otherwise match |
| `[skip tests]` | Skip tests (do **not** use on release commits) |
## Troubleshooting
| Symptom | Likely cause |
|---------|----------------|
| Release job skipped | No `[release]` in commit message, wrong branch, or tests failed/skipped |
| App token step fails | GitHub App credentials not configured on the repository |
| Verified commit rejected | Branch protection or App permissions |
| Tag already exists | `RELEASE_VERSION` was released before |
| Maven Central skipped | Non-GA version, or missing `[publish]` |
## Related files
- [`.github/workflows/ci.yml`](../.github/workflows/ci.yml) — CI pipeline
- [`.github/release-versions.yml`](../.github/release-versions.yml) — release version configuration
- [Alfresco build-tools `maven-release-slim`](https://github.com/Alfresco/alfresco-build-tools)
+1 -1
View File
@@ -10,7 +10,7 @@
<parent>
<groupId>org.alfresco.maven</groupId>
<artifactId>alfresco-sdk-aggregator</artifactId>
<version>4.17.0-A3-SNAPSHOT</version>
<version>4.17.0-A1</version>
<relativePath>../../pom.xml</relativePath>
</parent>
+1 -1
View File
@@ -8,7 +8,7 @@
<parent>
<groupId>org.alfresco.maven</groupId>
<artifactId>alfresco-sdk-aggregator</artifactId>
<version>4.17.0-A3-SNAPSHOT</version>
<version>4.17.0-A1</version>
<relativePath>../../pom.xml</relativePath>
</parent>
+1 -15
View File
@@ -3,7 +3,7 @@
<modelVersion>4.0.0</modelVersion>
<groupId>org.alfresco.maven</groupId>
<artifactId>alfresco-sdk-aggregator</artifactId>
<version>4.17.0-A3-SNAPSHOT</version>
<version>4.17.0-A1</version>
<name>Alfresco SDK</name>
<description>This aggregator Project builds all modules required for the Alfresco SDK</description>
<packaging>pom</packaging>
@@ -304,20 +304,6 @@
</properties>
</profile>
<!-- 25.5 -->
<profile>
<id>enterprise-255-tests</id>
<properties>
<alfresco.bomDependency.artifactId>acs-packaging</alfresco.bomDependency.artifactId>
<alfresco.platform.version>25.5.0.27</alfresco.platform.version>
<alfresco.share.docker.version>25.5.0-A.7</alfresco.share.docker.version>
<alfresco.share.version>25.5.0.28</alfresco.share.version>
<alfresco.platform.docker.image>quay.io/alfresco/alfresco-content-repository</alfresco.platform.docker.image>
<alfresco.share.docker.image>quay.io/alfresco/alfresco-share</alfresco.share.docker.image>
<alfresco.platform.docker.user>alfresco</alfresco.platform.docker.user>
</properties>
</profile>
<!-- 26.1 -->
<profile>
<id>community-261-tests</id>