You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将自制JAR包上传至Maven Central?求清晰操作步骤

Step-by-Step Guide to Upload Your JAR to Maven Central

I get it, the official docs can feel like reading a foreign language at times. Here’s a straight-to-the-point, no-fluff breakdown to get your JAR published to Maven Central without the headache:

Step 1: Get Sonatype OSSRH Access

Maven Central uses Sonatype’s OSS Repository Hosting (OSSRH) as the gateway for uploads. Here’s how to get in:

  • Create an account on Sonatype’s Jira platform.
  • Open a new support ticket requesting access to host your project. You’ll need to provide your group ID (e.g., io.github.yourusername for personal projects, com.yourcompany for business ones) and confirm you own the associated domain (if using a custom one).
  • Wait for approval (usually 1-2 business days). They’ll notify you once your staging repository is ready.

Step 2: Set Up GPG Signing

Maven Central requires all artifacts to be signed for integrity:

  • Install GPG (GPG4Win for Windows, GPGTools for Mac, or via your Linux package manager).
  • Generate a key pair with:
    gpg --gen-key
    
    Follow the prompts—use the same email linked to your Sonatype account and set a secure passphrase.
  • Publish your public key to a key server so others can verify your signature:
    gpg --send-keys --keyserver keys.openpgp.org YOUR_KEY_ID
    
    Get your key ID by running gpg --list-keys (it’s the long string under your name/email).

Step 3: Configure Your Maven POM & Settings

Update your project’s pom.xml with mandatory metadata and build config:

Key POM Additions

<!-- Distribution Management (points to Sonatype's repos) -->
<distributionManagement>
  <snapshotRepository>
    <id>ossrh</id>
    <url>https://s01.oss.sonatype.org/content/repositories/snapshots/</url>
  </snapshotRepository>
  <repository>
    <id>ossrh</id>
    <url>https://s01.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
  </repository>
</distributionManagement>

<!-- Build Plugins for Signing -->
<build>
  <plugins>
    <plugin>
      <groupId>org.apache.maven.plugins</groupId>
      <artifactId>maven-gpg-plugin</artifactId>
      <version>3.0.1</version>
      <executions>
        <execution>
          <id>sign-artifacts</id>
          <phase>verify</phase>
          <goals>
            <goal>sign</goal>
          </goals>
        </execution>
      </executions>
    </plugin>
  </plugins>
</build>

<!-- Mandatory Metadata -->
<name>Your Project Name</name>
<description>A short, clear description of your project</description>
<url>https://github.com/yourusername/yourproject</url>
<licenses>
  <license>
    <name>MIT License</name>
    <url>https://opensource.org/licenses/MIT</url>
  </license>
</licenses>
<developers>
  <developer>
    <name>Your Name</name>
    <email>your.email@example.com</email>
  </developer>
</developers>
<scm>
  <connection>scm:git:git://github.com/yourusername/yourproject.git</connection>
  <developerConnection>scm:git:ssh://github.com/yourusername/yourproject.git</developerConnection>
  <url>https://github.com/yourusername/yourproject</url>
</scm>

Update Maven Settings

Edit your ~/.m2/settings.xml (create it if it doesn’t exist) to add your Sonatype credentials:

<settings>
  <servers>
    <server>
      <id>ossrh</id>
      <username>your-sonatype-jira-username</username>
      <password>your-sonatype-jira-password</password>
    </server>
  </servers>
</settings>

Step 4: Deploy to Sonatype’s Staging Repo

Run this command from your project root to build, sign, and upload your JAR:

mvn clean deploy -Dgpg.passphrase=your-gpg-passphrase

This pushes your artifacts to a temporary staging repository on Sonatype’s servers.

Step 5: Release to Maven Central

Head to Sonatype’s Nexus Repository Manager (link provided in your approval email):

  • Log in with your Sonatype credentials.
  • Go to Build Promotion > Staging Repositories.
  • Find your staging repo (it’ll have a name like comyourcompany-1001).
  • Click Close—this runs validation checks (wait a few minutes for it to finish).
  • If validation passes, click Release to push your artifacts to Maven Central.

Final Notes

  • It takes 1-2 hours for your artifacts to show up in Maven Central’s search, but they’ll be downloadable immediately after release.
  • For snapshot versions, skip the close/release step—snapshots go straight to the Sonatype snapshot repo.
  • If validation fails during the close step, check the Nexus logs to fix issues (common culprits: missing metadata, unsigned artifacts, or invalid license info).

内容的提问来源于stack exchange,提问作者A X

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:21:10