如何从私有GitHub仓库发布Android库且不泄露源码?需AAR部署方案
方案实现指南(适配AGP 7.2.2 + Gradle 7.3.3)
一、临时方案:GitHub公开仓库托管AAR及Maven元数据
1. 生成完整的Maven发布文件
在你的Android库模块的build.gradle(Groovy)中添加Maven发布配置:
plugins { id 'com.android.library' id 'maven-publish' } android { // 保留你原有的库配置(compileSdk、defaultConfig等) } afterEvaluate { publishing { publications { release(MavenPublication) { from components.release // 自定义你的库标识信息 groupId = "com.github.your-username" artifactId = "your-library-name" version = "1.0.0" } } repositories { maven { // 指定本地生成Maven仓库的路径 url = uri("$buildDir/local-maven-repo") } } } }
执行Gradle任务生成文件:
./gradlew publishReleasePublicationToMavenRepository
执行完成后,build/local-maven-repo目录下会生成包含AAR、pom.xml、maven-metadata.xml的完整Maven目录结构。
2. 上传到GitHub公开仓库
- 创建一个新的公开GitHub仓库(或复用现有仓库的独立分支,比如
maven-repo) - 将
build/local-maven-repo下的所有文件完整保留目录结构复制到本地Git仓库目录 - 提交并推送文件到GitHub仓库的目标分支
3. 在项目中引入该库
在主项目的settings.gradle中添加仓库地址:
dependencyResolutionManagement { repositories { google() mavenCentral() // 添加你的GitHub Maven仓库地址 maven { url = uri("https://raw.githubusercontent.com/your-username/your-maven-repo/main/") content { includeGroup("com.github.your-username") } } } }
在应用模块的build.gradle中添加依赖:
dependencies { implementation 'com.github.your-username:your-library-name:1.0.0' }
二、永久解决方案:发布到MavenCentral
1. 前置准备
- 在Sonatype JIRA注册账号,提交项目申请(需关联GitHub账号验证组ID/域名所有权)
- 生成GPG密钥对,用于签名发布构件(确保密钥上传到公开密钥服务器)
2. 配置Gradle发布脚本
在库模块的build.gradle中添加签名与发布配置:
plugins { id 'com.android.library' id 'maven-publish' id 'signing' } android { // 保留原有的库配置 } // 从环境变量读取敏感信息,避免硬编码 def sonatypeUsername = System.getenv("SONATYPE_USERNAME") def sonatypePassword = System.getenv("SONATYPE_PASSWORD") def signingKeyId = System.getenv("SIGNING_KEY_ID") def signingPassword = System.getenv("SIGNING_PASSWORD") def signingSecretKeyRingFile = System.getenv("SIGNING_SECRET_KEY_RING_FILE") afterEvaluate { publishing { publications { release(MavenPublication) { from components.release groupId = "com.your-domain" artifactId = "your-library-name" version = "1.0.0" // 填充POM元数据(必填项) pom { name = "Your Library Name" description = "自定义Android库的功能描述" url = "https://github.com/your-username/your-library-repo" licenses { license { name = "The Apache License, Version 2.0" url = "http://www.apache.org/licenses/LICENSE-2.0.txt" } } developers { developer { id = "your-username" name = "Your Full Name" email = "your-email@example.com" } } scm { connection = "scm:git:git://github.com/your-username/your-library-repo.git" developerConnection = "scm:git:ssh://github.com/your-username/your-library-repo.git" url = "https://github.com/your-username/your-library-repo" } } } } repositories { maven { url = uri("https://s01.oss.sonatype.org/service/local/staging/deploy/maven2/") credentials { username = sonatypeUsername password = sonatypePassword } } } } // 配置构件签名 signing { sign publishing.publications.release } }
3. 完成发布流程
- 配置系统环境变量,填入Sonatype账号信息与GPG密钥信息
- 执行Gradle任务上传构件:
./gradlew publishReleasePublicationToMavenRepository
- 登录Sonatype Nexus仓库,找到对应的Staging Repository,执行Close和Release操作,等待构件同步到MavenCentral(通常需要1-2小时)
内容的提问来源于stack exchange,提问作者Manthan Vyas
相关产品推荐
相关产品推荐

