-
Notifications
You must be signed in to change notification settings - Fork 0
64 lines (58 loc) · 2.74 KB
/
Copy pathci.yml
File metadata and controls
64 lines (58 loc) · 2.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
name: CI
on:
pull_request:
push:
branches:
- main
# Least-privilege default; this workflow only reads the repo.
permissions:
contents: read
jobs:
quality:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
# JDK matrix is a list so we can expand as new LTS releases land.
# Current floor: 21 — set by pom.xml's <java.version>21</java.version>.
java-version: ["21"]
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Conformance catalog pinned by SHA (was: clone of the latest default
# branch). The single source of truth for the ref is the tracked
# `.conformance-catalog-ref` file at the repo root — bump it when adopting
# new catalog cases, together with the SDK-side conformance coverage, so a
# catalog change can never break CI on its own. The Checkout step above
# must precede this, which reads that file out of the workspace.
#
# The read/guard/fetch sequence lives in the script rather than inline
# here: more than one workflow needs it, and inline copies meant the
# 40-hex-SHA guard could be tightened in one and not the others. It checks
# the catalog out to $RUNNER_TEMP/conformance, outside the workspace, so
# release.yml's `git add -A` cannot stage it as an embedded gitlink.
- name: Check out shared conformance catalog (outside workspace)
run: .github/scripts/fetch-conformance-catalog.sh
- name: Setup Java
uses: actions/setup-java@c1e323688fd81a25caa38c78aa6df2d33d3e20d9 # v4.8.0
with:
distribution: temurin
java-version: ${{ matrix.java-version }}
cache: maven
- name: Verify and validate publish artifacts
# Single reactor pass covering all three modules (core, mcp, spring).
# - verify: compile + run unit tests + conformance tests + package
# + run bound plugins (checkstyle, jacoco, etc.)
# - source:jar / javadoc:jar: confirms the artifacts that will be
# published to Maven Central can be built.
# Must be one mvn invocation: `source:jar` / `javadoc:jar` are run
# directly (no phase), so splitting them off would leave the second
# invocation unable to resolve inter-module deps from ~/.m2 (we
# don't install).
#
# CONFORMANCE_CATALOG_PATH points at the catalog checked out in the
# previous step. This is the explicit override ConformanceCatalogPaths
# checks first, avoiding any path-resolution ambiguity.
env:
CONFORMANCE_CATALOG_PATH: ${{ runner.temp }}/conformance/oauth-sdk-conformance-catalog.yaml
run: mvn -B verify source:jar javadoc:jar