You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Gitlab CI环境下Maven生成源码包部署失败(400 Bad Request)问题求助

Fixing 400 Bad Request When Deploying Maven Sources Jar to GitLab Package Registry

I've run into this exact issue before, so let's break down what's going on and how to resolve it:

The Context

You've configured the maven-source-plugin to generate sources jars, and both local and GitLab CI builds successfully create your main JAR and sources JAR. But when running mvn deploy, the sources JAR upload fails with a 400 Bad Request. Removing the source plugin makes deploy work normally, so the problem is specific to how the sources artifact interacts with GitLab's registry.

Troubleshooting & Fixes

1. Verify GitLab Deployment Token Permissions

GitLab's Maven registry requires explicit permissions to upload artifacts. If you're using a project-level deployment token:

  • Go to your GitLab project → Settings → Repository → Deploy Tokens
  • Ensure the token has the write_package_registry permission enabled. For personal access tokens, you'll need both api and write_registry permissions.

2. Upgrade the Maven Deploy Plugin

Your error shows you're using maven-deploy-plugin:2.7—this version is outdated and has known compatibility issues with GitLab's modern Maven API. Update it in your POM's pluginManagement section:

<build>
  <pluginManagement>
    <plugins>
      <plugin>
        <groupId>org.apache.maven.plugins</groupId>
        <artifactId>maven-deploy-plugin</artifactId>
        <version>3.1.1</version>
      </plugin>
    </plugins>
  </pluginManagement>
</build>

3. Adjust the Maven Source Plugin Configuration

Switch the source plugin's goal to jar-no-fork (instead of jar) to avoid lifecycle conflicts that might corrupt the sources artifact metadata. Also upgrade the source plugin to a recent version:

<plugin>
  <groupId>org.apache.maven.plugins</groupId>
  <artifactId>maven-source-plugin</artifactId>
  <version>3.3.0</version>
  <executions>
    <execution>
      <id>attach-sources</id>
      <goals>
        <goal>jar-no-fork</goal>
      </goals>
    </execution>
  </executions>
</plugin>

4. Confirm Maven Settings & Repository IDs

Make sure your settings.xml and POM's distributionManagement use the exact same repository ID, and double-check the GitLab project ID in the URL:

settings.xml snippet:

<settings>
  <servers>
    <server>
      <id>gitlab-maven</id>
      <configuration>
        <httpHeaders>
          <property>
            <name>Private-Token</name>
            <value>YOUR_DEPLOY_TOKEN</value>
          </property>
        </httpHeaders>
      </configuration>
    </server>
  </servers>
  <profiles>
    <profile>
      <id>gitlab-maven</id>
      <repositories>
        <repository>
          <id>gitlab-maven</id>
          <url>https://gitlab.com/api/v4/projects/YOUR_PROJECT_ID/packages/maven</url>
          <releases><enabled>true</enabled></releases>
          <snapshots><enabled>true</enabled></snapshots>
        </repository>
      </repositories>
    </profile>
  </profiles>
  <activeProfiles>
    <activeProfile>gitlab-maven</activeProfile>
  </activeProfiles>
</settings>

POM distributionManagement:

<distributionManagement>
  <repository>
    <id>gitlab-maven</id>
    <url>https://gitlab.com/api/v4/projects/YOUR_PROJECT_ID/packages/maven</url>
  </repository>
  <snapshotRepository>
    <id>gitlab-maven</id>
    <url>https://gitlab.com/api/v4/projects/YOUR_PROJECT_ID/packages/maven</url>
  </snapshotRepository>
</distributionManagement>

5. Clear Stale GitLab Artifacts

If you've attempted to deploy this version before (even unsuccessfully), GitLab might have cached partial artifact data. Head to your project → Packages & Registries → Maven Repository, delete all artifacts for version 2.2, then run mvn clean deploy -DskipTests again.

Validation

Test the fix locally first with mvn clean deploy -DskipTests to confirm the sources jar uploads successfully, then run the GitLab CI pipeline to verify it works there too.

内容的提问来源于stack exchange,提问作者Kevin Day

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 18:03:12