Gitlab CI环境下Maven生成源码包部署失败(400 Bad Request)问题求助
I've run into this exact issue before, so let's break down what's going on and how to resolve it:
The Context
You've configured the maven-source-plugin to generate sources jars, and both local and GitLab CI builds successfully create your main JAR and sources JAR. But when running mvn deploy, the sources JAR upload fails with a 400 Bad Request. Removing the source plugin makes deploy work normally, so the problem is specific to how the sources artifact interacts with GitLab's registry.
Troubleshooting & Fixes
1. Verify GitLab Deployment Token Permissions
GitLab's Maven registry requires explicit permissions to upload artifacts. If you're using a project-level deployment token:
- Go to your GitLab project → Settings → Repository → Deploy Tokens
- Ensure the token has the
write_package_registrypermission enabled. For personal access tokens, you'll need bothapiandwrite_registrypermissions.
2. Upgrade the Maven Deploy Plugin
Your error shows you're using maven-deploy-plugin:2.7—this version is outdated and has known compatibility issues with GitLab's modern Maven API. Update it in your POM's pluginManagement section:
<build> <pluginManagement> <plugins> <plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-deploy-plugin</artifactId> <version>3.1.1</version> </plugin> </plugins> </pluginManagement> </build>
3. Adjust the Maven Source Plugin Configuration
Switch the source plugin's goal to jar-no-fork (instead of jar) to avoid lifecycle conflicts that might corrupt the sources artifact metadata. Also upgrade the source plugin to a recent version:
<plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-source-plugin</artifactId> <version>3.3.0</version> <executions> <execution> <id>attach-sources</id> <goals> <goal>jar-no-fork</goal> </goals> </execution> </executions> </plugin>
4. Confirm Maven Settings & Repository IDs
Make sure your settings.xml and POM's distributionManagement use the exact same repository ID, and double-check the GitLab project ID in the URL:
settings.xml snippet:
<settings> <servers> <server> <id>gitlab-maven</id> <configuration> <httpHeaders> <property> <name>Private-Token</name> <value>YOUR_DEPLOY_TOKEN</value> </property> </httpHeaders> </configuration> </server> </servers> <profiles> <profile> <id>gitlab-maven</id> <repositories> <repository> <id>gitlab-maven</id> <url>https://gitlab.com/api/v4/projects/YOUR_PROJECT_ID/packages/maven</url> <releases><enabled>true</enabled></releases> <snapshots><enabled>true</enabled></snapshots> </repository> </repositories> </profile> </profiles> <activeProfiles> <activeProfile>gitlab-maven</activeProfile> </activeProfiles> </settings>
POM distributionManagement:
<distributionManagement> <repository> <id>gitlab-maven</id> <url>https://gitlab.com/api/v4/projects/YOUR_PROJECT_ID/packages/maven</url> </repository> <snapshotRepository> <id>gitlab-maven</id> <url>https://gitlab.com/api/v4/projects/YOUR_PROJECT_ID/packages/maven</url> </snapshotRepository> </distributionManagement>
5. Clear Stale GitLab Artifacts
If you've attempted to deploy this version before (even unsuccessfully), GitLab might have cached partial artifact data. Head to your project → Packages & Registries → Maven Repository, delete all artifacts for version 2.2, then run mvn clean deploy -DskipTests again.
Validation
Test the fix locally first with mvn clean deploy -DskipTests to confirm the sources jar uploads successfully, then run the GitLab CI pipeline to verify it works there too.
内容的提问来源于stack exchange,提问作者Kevin Day

