From 461eeaafddcc4d305316e3138ae9f90f1028f66f Mon Sep 17 00:00:00 2001 From: Ryan Barlow <7389646+ryanbarlow97@users.noreply.github.com> Date: Tue, 22 Sep 2026 15:28:02 +0000 Subject: [PATCH] ci: build dated development jars and tagged draft releases --- .github/dependencies.sha256 | 9 ++ .github/scripts/prepare-release.sh | 15 ++++ .github/workflows/build.yml | 55 ++++++++++++ .github/workflows/maven-release.yml | 135 ++++++++++++++++++++++++++++ .github/workflows/release.yml | 20 +++++ .gitignore | 5 +- pom.xml | 55 ++++++------ 7 files changed, 263 insertions(+), 31 deletions(-) create mode 100644 .github/dependencies.sha256 create mode 100644 .github/scripts/prepare-release.sh create mode 100644 .github/workflows/build.yml create mode 100644 .github/workflows/maven-release.yml create mode 100644 .github/workflows/release.yml diff --git a/.github/dependencies.sha256 b/.github/dependencies.sha256 new file mode 100644 index 0000000..3545e7e --- /dev/null +++ b/.github/dependencies.sha256 @@ -0,0 +1,9 @@ +086e3971ea63c0b5ad567881b2dfd955acbbffa24fe85ceac8abf54b114ce986 libs/api-5.4.jar +4241c14a7727c34feea6507ec801318a3d4a90f070e4525681079fb94ee4c593 libs/gson-2.10.1.jar +c84700df5942fd969d3e8c2f1ad2c3ebeb17987ef88b426408d1306e49c4aada libs/MMOItems-6.10.jar +660ff2a6ec86bc8d7779948cf65c1637e271a16e1ef812d6a273f4a5c5eec73c libs/MythicLib-1.7.jar +97e0c708c1e319189ce1cda049244551a105860d51e908d2bcbc183fd1f89816 libs/spigot-api-1.20.2-R0.1-SNAPSHOT.jar +1edf7fcea79a16b8dfdd3bc988ddec7f8908b1f7762fdf00d39acb037542747a libs/json-20220320.jar +2d9484f4c649f708f47f9a479465fc729770ee65617dca3011836602264f6439 libs/json-simple-1.1.jar +22dd8755e769823585340354c567cd6c3d07ddb6410747ce8f27bb97d3475b04 libs/denareconomy-0.1.8.jar +5185b9e0ea8653ab61da07304f1573c6a9a5af97cf55a5d970c5a25f16bc743d libs/simplefactions-2.8.7.jar diff --git a/.github/scripts/prepare-release.sh b/.github/scripts/prepare-release.sh new file mode 100644 index 0000000..b24a316 --- /dev/null +++ b/.github/scripts/prepare-release.sh @@ -0,0 +1,15 @@ +#!/usr/bin/env bash +set -euo pipefail +: "${GH_TOKEN:?Set DEPS_TOKEN with Contents read access to TF-Minecraft/ServerAssets}" +ref=8a44414cd5b74b7d1c7a258ccf5a86a5f6e0294b +mkdir -p libs +curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/086e3971ea63/api-5.4.jar?ref=$ref" > "libs/api-5.4.jar" +curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/4241c14a7727/gson-2.10.1.jar?ref=$ref" > "libs/gson-2.10.1.jar" +curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/c84700df5942/MMOItems-6.10.jar?ref=$ref" > "libs/MMOItems-6.10.jar" +curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/660ff2a6ec86/MythicLib-1.7.jar?ref=$ref" > "libs/MythicLib-1.7.jar" +curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/97e0c708c1e3/spigot-api-1.20.2-R0.1-SNAPSHOT.jar?ref=$ref" > "libs/spigot-api-1.20.2-R0.1-SNAPSHOT.jar" +curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/1edf7fcea79a/json-20220320.jar?ref=$ref" > "libs/json-20220320.jar" +curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/2d9484f4c649/json-simple-1.1.jar?ref=$ref" > "libs/json-simple-1.1.jar" +curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/22dd8755e769/denareconomy-0.1.8.jar?ref=$ref" > "libs/denareconomy-0.1.8.jar" +curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/5185b9e0ea86/simplefactions-2.8.7.jar?ref=$ref" > "libs/simplefactions-2.8.7.jar" +sha256sum --check .github/dependencies.sha256 diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml new file mode 100644 index 0000000..66b7bea --- /dev/null +++ b/.github/workflows/build.yml @@ -0,0 +1,55 @@ +name: Build + +on: + push: + branches: [main] + pull_request: + branches: [main] + +permissions: + contents: read + +jobs: + build: + runs-on: ubuntu-24.04 + timeout-minutes: 20 + steps: + - uses: actions/checkout@v7 + with: + persist-credentials: false + - uses: actions/setup-java@v6 + with: + distribution: temurin + java-version: '25' + - name: Prepare pinned dependencies + env: + GH_TOKEN: ${{ secrets.DEPS_TOKEN }} + run: bash .github/scripts/prepare-release.sh + - name: Set dated development version + id: dev + shell: bash + run: | + dev_version="DEV-$(date -u +%Y%m%d-%H%M)" + mvn -B --no-transfer-progress org.codehaus.mojo:versions-maven-plugin:2.22.0:set \ + -DnewVersion="$dev_version" -DgenerateBackupPoms=false + mvn -B --no-transfer-progress help:evaluate \ + -Dexpression=project.build.finalName -Doutput="$RUNNER_TEMP/final-name" + final_name=$(cat "$RUNNER_TEMP/final-name") + echo "name=$final_name" >> "$GITHUB_OUTPUT" + echo "jar=target/$final_name.jar" >> "$GITHUB_OUTPUT" + + - name: Run unit tests and build + run: mvn -B --no-transfer-progress clean verify -DskipTests=false -Dmaven.test.skip=false + - uses: actions/upload-artifact@v7 + with: + name: ${{ steps.dev.outputs.name }}-${{ github.run_id }}-${{ github.run_attempt }} + path: ${{ steps.dev.outputs.jar }} + if-no-files-found: error + + - name: Upload unit test reports + if: ${{ !cancelled() && hashFiles('target/surefire-reports/*.xml') != '' }} + uses: actions/upload-artifact@v7 + with: + name: unit-test-reports-${{ github.run_id }}-${{ github.run_attempt }} + path: target/surefire-reports/ + if-no-files-found: error diff --git a/.github/workflows/maven-release.yml b/.github/workflows/maven-release.yml new file mode 100644 index 0000000..3103b70 --- /dev/null +++ b/.github/workflows/maven-release.yml @@ -0,0 +1,135 @@ +name: Maven plugin release + +on: + workflow_call: + inputs: + java-version: + required: true + type: string + artifact-path: + description: Exact deployable JAR path, with optional {version} placeholder + required: true + type: string + secrets: + DEPS_TOKEN: + required: false + +permissions: + contents: read + +concurrency: + group: plugin-release-${{ github.repository }}-${{ github.ref }} + cancel-in-progress: false + +defaults: + run: + shell: bash + +jobs: + build: + if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') + runs-on: ubuntu-24.04 + timeout-minutes: 20 + steps: + - uses: actions/checkout@v7 + with: + persist-credentials: false + + - uses: actions/setup-java@v6 + with: + distribution: temurin + java-version: ${{ inputs.java-version }} + + - name: Validate release version + env: + TAG: ${{ github.ref_name }} + run: | + [[ "$TAG" =~ ^v[0-9]+\.[0-9]+(\.[0-9]+)?(-[0-9A-Za-z]+([.-][0-9A-Za-z]+)*)?$ ]] || { + echo '::error::Expected vMAJOR.MINOR or vMAJOR.MINOR.PATCH, with an optional prerelease suffix.' + exit 1 + } + [[ "${TAG^^}" != *SNAPSHOT* ]] || exit 1 + + - name: Prepare pinned dependencies + env: + GH_TOKEN: ${{ secrets.DEPS_TOKEN }} + run: | + if [[ -f .github/scripts/prepare-release.sh ]]; then + bash .github/scripts/prepare-release.sh + fi + + - name: Check Maven version and build + env: + TAG: ${{ github.ref_name }} + run: | + version_file="$RUNNER_TEMP/maven-release-version" + mvn -B --no-transfer-progress -P'!deploy-live' help:evaluate \ + -Dexpression=project.version -Doutput="$version_file" + [[ "$(cat "$version_file")" == "${TAG#v}" ]] || { + echo '::error::The tag must match project.version exactly.' + exit 1 + } + mvn -B --no-transfer-progress -P'!deploy-live' clean verify + + - name: Stage only the release JAR + env: + ARTIFACT_PATH: ${{ inputs.artifact-path }} + TAG: ${{ github.ref_name }} + run: | + python3 - <<'PY' + import hashlib, json, os, pathlib, shutil, zipfile + root = pathlib.Path.cwd().resolve() + source = (root / os.environ['ARTIFACT_PATH'].replace('{version}', os.environ['TAG'][1:])).resolve() + if not source.is_relative_to(root / 'target') or not source.is_file() or source.suffix != '.jar': + raise SystemExit('Expected one existing JAR inside target/') + with zipfile.ZipFile(source) as jar: + if not {'plugin.yml', 'paper-plugin.yml'}.intersection(jar.namelist()): + raise SystemExit('Release JAR has no plugin descriptor') + if jar.testzip() is not None: + raise SystemExit('Release JAR is corrupt') + dest = pathlib.Path(os.environ['RUNNER_TEMP']) / 'plugin-release' + dest.mkdir() + shutil.copyfile(source, dest / source.name) + digest = hashlib.sha256((dest / source.name).read_bytes()).hexdigest() + (dest / 'SHA256SUMS').write_text(f'{digest} {source.name}\n') + (dest / 'build.json').write_text(json.dumps({ + 'repository': os.environ['GITHUB_REPOSITORY'], + 'commit': os.environ['GITHUB_SHA'], + 'tag': os.environ['TAG'], + 'run': f"{os.environ['GITHUB_SERVER_URL']}/{os.environ['GITHUB_REPOSITORY']}/actions/runs/{os.environ['GITHUB_RUN_ID']}", + 'artifact': source.name, + 'sha256': digest, + }, indent=2) + '\n') + PY + + - uses: actions/upload-artifact@v7 + with: + name: plugin-release-${{ github.sha }} + path: ${{ runner.temp }}/plugin-release/ + if-no-files-found: error + retention-days: 30 + + publish: + needs: build + runs-on: ubuntu-24.04 + timeout-minutes: 5 + permissions: + contents: write + steps: + - uses: actions/download-artifact@v8 + with: + name: plugin-release-${{ github.sha }} + path: release + + - name: Create draft release + working-directory: release + env: + GH_TOKEN: ${{ github.token }} + GH_REPO: ${{ github.repository }} + TAG: ${{ github.ref_name }} + run: | + sha256sum --check SHA256SUMS + flags=() + if [[ "$TAG" == *-* ]]; then flags+=(--prerelease); fi + gh release create "$TAG" ./*.jar SHA256SUMS build.json \ + --verify-tag --draft --title "$TAG" --generate-notes "${flags[@]}" diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..42ee700 --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,20 @@ +name: Release + +on: + push: + tags: ['v*'] + +permissions: + contents: read + +jobs: + release: + permissions: + contents: write + uses: ./.github/workflows/maven-release.yml + with: + java-version: '25' + # Exact path, not a glob. {version} is replaced with the tag without v. + artifact-path: target/bartershops-{version}.jar + secrets: + DEPS_TOKEN: ${{ secrets.DEPS_TOKEN }} diff --git a/.gitignore b/.gitignore index 5d8b59c..96afe12 100644 --- a/.gitignore +++ b/.gitignore @@ -30,4 +30,7 @@ nbdist/ Thumbs.db # Logs -*.log \ No newline at end of file +*.log + +# Downloaded build dependencies +/libs/*.jar diff --git a/pom.xml b/pom.xml index 9ecef5f..222d8d7 100644 --- a/pom.xml +++ b/pom.xml @@ -11,7 +11,6 @@ 17 17 - D:/Dokumenter/My Plugins/VSCode Workspace/simplefactions/target @@ -20,84 +19,80 @@ api 5.4 system - D:/Dokumenter/My Plugins/Reference Libs/api-5.4.jar + ${project.basedir}/libs/api-5.4.jar local - api + gson 2.10.1 system - D:/Dokumenter/My Plugins/Reference Libs/gson-2.10.1.jar + ${project.basedir}/libs/gson-2.10.1.jar local MMOItems 6.10 system - D:/Dokumenter/My Plugins/Reference Libs/MMOItems-6.10.jar + ${project.basedir}/libs/MMOItems-6.10.jar local MythicLib - 1.6.1 + 1.7 system - D:/Dokumenter/My Plugins/Reference Libs/MythicLib-1.7.jar + ${project.basedir}/libs/MythicLib-1.7.jar local spigot-api 1.20.2-R0.1-SNAPSHOT system - D:/Dokumenter/My Plugins/Reference Libs/spigot-api-1.20.2-R0.1-SNAPSHOT.jar + ${project.basedir}/libs/spigot-api-1.20.2-R0.1-SNAPSHOT.jar local json 20220320 system - D:/Dokumenter/My Plugins/Reference Libs/json-20220320.jar + ${project.basedir}/libs/json-20220320.jar local json-simple 1.1 system - D:/Dokumenter/My Plugins/Reference Libs/json-simple-1.1.jar + ${project.basedir}/libs/json-simple-1.1.jar local - TLibs - 0.1.2 + DenarEconomy + 0.1.8 system - D:/Dokumenter/My Plugins/TFMC/DenarEconomy/denareconomy-0.1.2.jar + ${project.basedir}/libs/denareconomy-0.1.8.jar local simplefactions 2.8.7 system - ${tfmc.simplefactions}/simplefactions-2.8.7.jar + ${project.basedir}/libs/simplefactions-2.8.7.jar + + + src/main/resources + true + plugin.yml + + + src/main/resources + false + plugin.yml + + - - org.apache.maven.plugins - maven-antrun-plugin - - - package - run - - - - - - - -