Skip to content

Commit fbebf10

Browse files
authored
ci: add verified UTC development and release builds (#2)
1 parent 62e9c18 commit fbebf10

8 files changed

Lines changed: 248 additions & 24 deletions

File tree

‎.github/dependencies.sha256‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
b7156eab567772f9fdac0bf696b209111790c3f69149ab9a742e3dd030ec4b10 libs/spigot-api.jar
2+
3bc6fa2477eb30f840d14c6b9e7074d8326ef9a100add8a6db89e85ecf53a3f2 libs/BungeeCord.jar

‎.github/scripts/prepare-release.sh‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
#!/usr/bin/env bash
2+
set -euo pipefail
3+
: "${GH_TOKEN:?Set DEPS_TOKEN with Contents read access to TF-Minecraft/ServerAssets}"
4+
ref=726208728d6b3b66d09e5efcdfab9a63b8e39228
5+
mkdir -p libs
6+
curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/b7156eab5677/spigot-api.jar?ref=$ref" > "libs/spigot-api.jar"
7+
curl --fail --location --silent --show-error --retry 3 -H "Authorization: Bearer $GH_TOKEN" -H "Accept: application/vnd.github.raw+json" "https://api.github.com/repos/TF-Minecraft/ServerAssets/contents/jars/3bc6fa2477eb/BungeeCord.jar?ref=$ref" > "libs/BungeeCord.jar"
8+
sha256sum --check .github/dependencies.sha256

‎.github/workflows/build.yml‎

Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
name: Build
2+
3+
on:
4+
push:
5+
branches: [main]
6+
pull_request:
7+
branches: [main]
8+
9+
permissions:
10+
contents: read
11+
12+
jobs:
13+
build:
14+
runs-on: ubuntu-24.04
15+
timeout-minutes: 20
16+
steps:
17+
- uses: actions/checkout@v7
18+
with:
19+
persist-credentials: false
20+
- uses: actions/setup-java@v6
21+
with:
22+
distribution: temurin
23+
java-version: '25'
24+
- name: Install pinned TLibs in Maven
25+
uses: TF-Minecraft/TLibs/.github/actions/setup@905a196217471252b96be5ecf8eeb16c9e85e41d
26+
with:
27+
token: ${{ secrets.DEPS_TOKEN }}
28+
29+
- name: Prepare pinned dependencies
30+
env:
31+
GH_TOKEN: ${{ secrets.DEPS_TOKEN }}
32+
run: bash .github/scripts/prepare-release.sh
33+
- name: Set dated development version
34+
id: dev
35+
shell: bash
36+
run: |
37+
dev_version="DEV-$(date -u +%Y%m%d-%H%M)"
38+
mvn -B --no-transfer-progress org.codehaus.mojo:versions-maven-plugin:2.22.0:set \
39+
-DnewVersion="$dev_version" -DgenerateBackupPoms=false
40+
mvn -B --no-transfer-progress help:evaluate \
41+
-Dexpression=project.build.finalName -Doutput="$RUNNER_TEMP/final-name"
42+
final_name=$(cat "$RUNNER_TEMP/final-name")
43+
echo "name=$final_name" >> "$GITHUB_OUTPUT"
44+
echo "jar=target/$final_name.jar" >> "$GITHUB_OUTPUT"
45+
46+
- name: Run unit tests and build
47+
run: mvn -B --no-transfer-progress clean verify -DskipTests=false -Dmaven.test.skip=false
48+
- uses: actions/upload-artifact@v7
49+
with:
50+
name: ${{ steps.dev.outputs.name }}-${{ github.run_id }}-${{ github.run_attempt }}
51+
path: ${{ steps.dev.outputs.jar }}
52+
if-no-files-found: error
53+
54+
- name: Upload unit test reports
55+
if: ${{ !cancelled() && hashFiles('target/surefire-reports/*.xml') != '' }}
56+
uses: actions/upload-artifact@v7
57+
with:
58+
name: unit-test-reports-${{ github.run_id }}-${{ github.run_attempt }}
59+
path: target/surefire-reports/
60+
if-no-files-found: error
Lines changed: 140 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,140 @@
1+
name: Maven plugin release
2+
3+
on:
4+
workflow_call:
5+
inputs:
6+
java-version:
7+
required: true
8+
type: string
9+
artifact-path:
10+
description: Exact deployable JAR path, with optional {version} placeholder
11+
required: true
12+
type: string
13+
secrets:
14+
DEPS_TOKEN:
15+
required: false
16+
17+
permissions:
18+
contents: read
19+
20+
concurrency:
21+
group: plugin-release-${{ github.repository }}-${{ github.ref }}
22+
cancel-in-progress: false
23+
24+
defaults:
25+
run:
26+
shell: bash
27+
28+
jobs:
29+
build:
30+
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
31+
runs-on: ubuntu-24.04
32+
timeout-minutes: 20
33+
steps:
34+
- uses: actions/checkout@v7
35+
with:
36+
persist-credentials: false
37+
38+
- uses: actions/setup-java@v6
39+
with:
40+
distribution: temurin
41+
java-version: ${{ inputs.java-version }}
42+
43+
- name: Validate release version
44+
env:
45+
TAG: ${{ github.ref_name }}
46+
run: |
47+
[[ "$TAG" =~ ^v[0-9]+\.[0-9]+(\.[0-9]+)?(-[0-9A-Za-z]+([.-][0-9A-Za-z]+)*)?$ ]] || {
48+
echo '::error::Expected vMAJOR.MINOR or vMAJOR.MINOR.PATCH, with an optional prerelease suffix.'
49+
exit 1
50+
}
51+
[[ "${TAG^^}" != *SNAPSHOT* ]] || exit 1
52+
53+
- name: Install pinned TLibs in Maven
54+
uses: TF-Minecraft/TLibs/.github/actions/setup@905a196217471252b96be5ecf8eeb16c9e85e41d
55+
with:
56+
token: ${{ secrets.DEPS_TOKEN }}
57+
58+
- name: Prepare pinned dependencies
59+
env:
60+
GH_TOKEN: ${{ secrets.DEPS_TOKEN }}
61+
run: |
62+
if [[ -f .github/scripts/prepare-release.sh ]]; then
63+
bash .github/scripts/prepare-release.sh
64+
fi
65+
66+
- name: Check Maven version and build
67+
env:
68+
TAG: ${{ github.ref_name }}
69+
run: |
70+
version_file="$RUNNER_TEMP/maven-release-version"
71+
mvn -B --no-transfer-progress -P'!deploy-live' help:evaluate \
72+
-Dexpression=project.version -Doutput="$version_file"
73+
[[ "$(cat "$version_file")" == "${TAG#v}" ]] || {
74+
echo '::error::The tag must match project.version exactly.'
75+
exit 1
76+
}
77+
mvn -B --no-transfer-progress -P'!deploy-live' clean verify
78+
79+
- name: Stage only the release JAR
80+
env:
81+
ARTIFACT_PATH: ${{ inputs.artifact-path }}
82+
TAG: ${{ github.ref_name }}
83+
run: |
84+
python3 - <<'PY'
85+
import hashlib, json, os, pathlib, shutil, zipfile
86+
root = pathlib.Path.cwd().resolve()
87+
source = (root / os.environ['ARTIFACT_PATH'].replace('{version}', os.environ['TAG'][1:])).resolve()
88+
if not source.is_relative_to(root / 'target') or not source.is_file() or source.suffix != '.jar':
89+
raise SystemExit('Expected one existing JAR inside target/')
90+
with zipfile.ZipFile(source) as jar:
91+
if not {'plugin.yml', 'paper-plugin.yml'}.intersection(jar.namelist()):
92+
raise SystemExit('Release JAR has no plugin descriptor')
93+
if jar.testzip() is not None:
94+
raise SystemExit('Release JAR is corrupt')
95+
dest = pathlib.Path(os.environ['RUNNER_TEMP']) / 'plugin-release'
96+
dest.mkdir()
97+
shutil.copyfile(source, dest / source.name)
98+
digest = hashlib.sha256((dest / source.name).read_bytes()).hexdigest()
99+
(dest / 'SHA256SUMS').write_text(f'{digest} {source.name}\n')
100+
(dest / 'build.json').write_text(json.dumps({
101+
'repository': os.environ['GITHUB_REPOSITORY'],
102+
'commit': os.environ['GITHUB_SHA'],
103+
'tag': os.environ['TAG'],
104+
'run': f"{os.environ['GITHUB_SERVER_URL']}/{os.environ['GITHUB_REPOSITORY']}/actions/runs/{os.environ['GITHUB_RUN_ID']}",
105+
'artifact': source.name,
106+
'sha256': digest,
107+
}, indent=2) + '\n')
108+
PY
109+
110+
- uses: actions/upload-artifact@v7
111+
with:
112+
name: plugin-release-${{ github.sha }}
113+
path: ${{ runner.temp }}/plugin-release/
114+
if-no-files-found: error
115+
retention-days: 30
116+
117+
publish:
118+
needs: build
119+
runs-on: ubuntu-24.04
120+
timeout-minutes: 5
121+
permissions:
122+
contents: write
123+
steps:
124+
- uses: actions/download-artifact@v8
125+
with:
126+
name: plugin-release-${{ github.sha }}
127+
path: release
128+
129+
- name: Create draft release
130+
working-directory: release
131+
env:
132+
GH_TOKEN: ${{ github.token }}
133+
GH_REPO: ${{ github.repository }}
134+
TAG: ${{ github.ref_name }}
135+
run: |
136+
sha256sum --check SHA256SUMS
137+
flags=()
138+
if [[ "$TAG" == *-* ]]; then flags+=(--prerelease); fi
139+
gh release create "$TAG" ./*.jar SHA256SUMS build.json \
140+
--verify-tag --draft --title "$TAG" --generate-notes "${flags[@]}"

‎.github/workflows/release.yml‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
name: Release
2+
3+
on:
4+
push:
5+
tags: ['v*']
6+
7+
permissions:
8+
contents: read
9+
10+
jobs:
11+
release:
12+
permissions:
13+
contents: write
14+
uses: ./.github/workflows/maven-release.yml
15+
with:
16+
java-version: '25'
17+
# Exact path, not a glob. {version} is replaced with the tag without v.
18+
artifact-path: target/tfmcweb-{version}.jar
19+
secrets:
20+
DEPS_TOKEN: ${{ secrets.DEPS_TOKEN }}

‎.gitignore‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -45,3 +45,6 @@ Desktop.ini
4545

4646
# Logs
4747
*.log
48+
49+
# Downloaded build dependencies
50+
/libs/*.jar

‎pom.xml‎

Lines changed: 14 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -13,9 +13,6 @@
1313
<maven.compiler.source>17</maven.compiler.source>
1414
<maven.compiler.target>17</maven.compiler.target>
1515
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
16-
<tfmc.refs>D:/Dokumenter/My Plugins/Reference Libs</tfmc.refs>
17-
<tfmc.builds>D:/Dokumenter/My Plugins/TFMC/TFMCWeb</tfmc.builds>
18-
1916
</properties>
2017

2118
<dependencies>
@@ -24,15 +21,15 @@
2421
<artifactId>spigot-api</artifactId>
2522
<version>1.21.8</version>
2623
<scope>system</scope>
27-
<systemPath>${tfmc.refs}/spigot-api.jar</systemPath>
24+
<systemPath>${project.basedir}/libs/spigot-api.jar</systemPath>
2825
</dependency>
2926

3027
<dependency>
3128
<groupId>net.md-5</groupId>
3229
<artifactId>bungeecord-chat</artifactId>
3330
<version>1.20-R0.1</version>
3431
<scope>system</scope>
35-
<systemPath>${tfmc.refs}/BungeeCord.jar</systemPath>
32+
<systemPath>${project.basedir}/libs/BungeeCord.jar</systemPath>
3633
</dependency>
3734

3835
<dependency>
@@ -49,25 +46,19 @@
4946
</dependencies>
5047

5148
<build>
49+
<resources>
50+
<resource>
51+
<directory>src/main/resources</directory>
52+
<filtering>true</filtering>
53+
<includes><include>plugin.yml</include></includes>
54+
</resource>
55+
<resource>
56+
<directory>src/main/resources</directory>
57+
<filtering>false</filtering>
58+
<excludes><exclude>plugin.yml</exclude></excludes>
59+
</resource>
60+
</resources>
5261
<plugins>
53-
<plugin>
54-
<groupId>org.apache.maven.plugins</groupId>
55-
<artifactId>maven-antrun-plugin</artifactId>
56-
<version>3.1.0</version>
57-
<executions>
58-
<execution>
59-
<phase>package</phase>
60-
<goals><goal>run</goal></goals>
61-
<configuration>
62-
<target>
63-
<mkdir dir="${tfmc.builds}"/>
64-
<copy file="${project.build.directory}/${project.build.finalName}.jar"
65-
tofile="${tfmc.builds}/${project.build.finalName}.jar"/>
66-
</target>
67-
</configuration>
68-
</execution>
69-
</executions>
70-
</plugin>
7162
</plugins>
7263
</build>
7364
</project>

‎src/main/resources/plugin.yml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
main: net.tfminecraft.TFMCWeb.TFMCWeb
22
api-version: 1.20
33
name: TFMCWeb
4-
version: 1.0
4+
version: ${project.version}
55
author: TFMC
66

77
depend: [TLibs]

0 commit comments

Comments
 (0)