修复actions/setup-java@v3中maven-gpg-plugin GPG密钥短语解密失败问题
解决GitHub Action中maven-gpg-plugin签名失败问题
概述
我正在开发一款自动发布Java库的GitHub Action,开发分支:https://github.com/MathieuSoysal/Java-maven-library-publisher/tree/2-add-automated-tests
Action的YAML代码
name: Java maven library publisher author: "Mathieu Soysal (@MathieuSoysal)" description: "Build automatically Java Maven library and publish it to GitHub Packages and Maven Central." branding: icon: "package" color: "gray-dark" inputs: nexus-username: description: "Nexus username" required: true nexus-password: description: "Nexus password" required: true gpg-private-key: description: "GPG private key" required: true gpg-passphrase: description: "GPG passphrase" required: true github-token: description: "GitHub token" required: true # Java version to use java-version: description: "Java version to use" required: true default: "17" # Library version library-version: description: "Library version" required: false default: "" runs: using: "composite" steps: - name: Checkout uses: actions/checkout@v3 - name: Set up JDK 17 for deploy to OSSRH uses: actions/setup-java@v3 with: distribution: "adopt" java-version: ${{ inputs.java-version }} server-id: ossrh server-username: ${{ inputs.nexus-username }} server-password: ${{ inputs.nexus-password }} gpg-private-key: ${{ inputs.gpg-private-key }} gpg-passphrase: ${{ inputs.gpg-passphrase }} - name: Build with Maven run: mvn -B package --file pom.xml shell: bash - name: Update package version if: ${{ inputs.library-version != '' }} run: mvn versions:set -DnewVersion=${{ inputs.library-version }} shell: bash - name: Prepare Maven environnement with Java 17 for deployment to OSSRH run: export MAVEN_OPTS="--add-opens=java.base/java.util=ALL-UNNAMED --add-opens=java.base/java.lang.reflect=ALL-UNNAMED --add-opens=java.base/java.text=ALL-UNNAMED --add-opens=java.desktop/java.awt.font=ALL-UNNAMED" shell: bash - name: Publish to Apache Maven Central run: mvn deploy -PossrhDeploy shell: bash env: MAVEN_USERNAME: ${{ inputs.nexus-username }} MAVEN_CENTRAL_TOKEN: ${{ inputs.nexus-password }} MAVEN_GPG_PASSPHRASE: ${{ inputs.gpg-passphrase }} - name: Set up JDK 17 for deploy to github packages uses: actions/setup-java@v3 with: distribution: "adopt" java-version: ${{ inputs.java-version }} server-id: github - name: Publish to GitHub Packages Apache Maven run: mvn deploy -PgithubDeploy shell: bash env: GITHUB_TOKEN: ${{ inputs.github-token }}
代码链接:action.yaml
测试工作流代码
name: Test Actions on: [push] jobs: test: runs-on: ubuntu-latest steps: - uses: actions/checkout@v3 - name: Maven Library build and publish uses: ./ with: nexus-username: ${{ secrets.NEXUS_USERNAME }} nexus-password: ${{ secrets.NEXUS_PASSWORD }} gpg-private-key: ${{ secrets.GPG_PRIVATE_KEY }} gpg-passphrase: ${{ secrets.GPG_PASSPHRASE }} library-version: $GITHUB_RUN_NUMBER github-token: ${{ secrets.GITHUB_TOKEN }} java-version: 17
代码链接:test-action.yml
错误信息
[INFO] Building jar: /home/runner/work/Java-maven-library-publisher/Java-maven-library-publisher/target/template-6-javadoc.jar [INFO] [INFO] --- maven-gpg-plugin:3.0.1:sign (sign-artifacts) @ template --- [INFO] ------------------------------------------------------------------------ [INFO] BUILD FAILURE [INFO] ------------------------------------------------------------------------ [INFO] Total time: 14.831 s [INFO] Finished at: 2022-12-24T15:58:31Z [INFO] ------------------------------------------------------------------------ Error: Failed to execute goal org.apache.maven.plugins:maven-gpg-plugin:3.0.1:sign (sign-artifacts) on project template: Unable to decrypt gpg passphrase: org.sonatype.plexus.components.sec.dispatcher.SecDispatcherException: java.io.FileNotFoundException: /home/runner/.m2/settings-security.xml (No such file or directory) -> [Help 1] Error: Error: To see the full stack trace of the errors, re-run Maven with the -e switch. Error: Re-run Maven using the -X switch to enable full debug logging. Error: Error: For more information about the errors and possible solutions, please read the following articles: Error: [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoFailureException Error: Process completed with exit code 1.
解决方法
1. 修改maven-gpg-plugin配置
问题根源在于maven-gpg-plugin默认尝试从settings-security.xml读取GPG密码,但该文件在GitHub Runner环境中不存在。直接在项目的pom.xml中配置插件,让它读取环境变量传递的密码,并启用无交互模式:
<plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-gpg-plugin</artifactId> <version>3.0.1</version> <executions> <execution> <id>sign-artifacts</id> <phase>verify</phase> <goals> <goal>sign</goal> </goals> </execution> </executions> <configuration> <!-- 直接读取环境变量中的GPG密码 --> <passphrase>${env.MAVEN_GPG_PASSPHRASE}</passphrase> <!-- 启用loopback模式,避免交互式密码输入 --> <gpgArguments> <arg>--pinentry-mode</arg> <arg>loopback</arg> </gpgArguments> </configuration> </plugin>
2. 调整Action步骤顺序
当前Action中先执行Build with Maven再更新版本,会导致构建的是旧版本产物,后续发布的版本不匹配。将版本更新步骤移到构建之前:
- name: Update package version if: ${{ inputs.library-version != '' }} run: mvn versions:set -DnewVersion=${{ inputs.library-version }} shell: bash - name: Build with Maven run: mvn -B package --file pom.xml shell: bash
3. 验证环境变量传递
确保Publish to Apache Maven Central步骤中已经正确传递MAVEN_GPG_PASSPHRASE环境变量,该变量会被上述插件配置读取,无需依赖settings-security.xml。
通过以上调整,maven-gpg-plugin就能直接使用环境变量中的密码完成签名,避免读取不存在的配置文件,从而解决构建失败问题。
内容的提问来源于stack exchange,提问作者ThrowsError
相关产品推荐
相关产品推荐

