mirror of
https://github.com/actions/setup-java.git
synced 2026-07-29 09:05:56 +00:00
Use gpg.passphraseEnvName instead of gpg.passphrase server
The maven-gpg-plugin's `gpg.passphrase`/`passphraseServerId` mechanism is deprecated and fails when the plugin's `bestPractices` mode is enabled. Stop writing the `gpg.passphrase` server to settings.xml and instead set `gpg.passphraseEnvName` via an active profile when the configured passphrase env var name differs from the plugin default (MAVEN_GPG_PASSPHRASE). The default `gpg-passphrase` input value (GPG_PASSPHRASE) is unchanged, so the plugin reads the same environment variable as before. Fixes #760 Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
parent
81c13a41f9
commit
3384951fff
@ -228,9 +228,40 @@ describe('auth tests', () => {
|
|||||||
<username>\${env.${username}}</username>
|
<username>\${env.${username}}</username>
|
||||||
<password>\${env.&<>"''"><&}</password>
|
<password>\${env.&<>"''"><&}</password>
|
||||||
</server>
|
</server>
|
||||||
|
</servers>
|
||||||
|
<profiles>
|
||||||
|
<profile>
|
||||||
|
<id>setup-java-gpg</id>
|
||||||
|
<properties>
|
||||||
|
<gpg.passphraseEnvName>${gpgPassphrase}</gpg.passphraseEnvName>
|
||||||
|
</properties>
|
||||||
|
</profile>
|
||||||
|
</profiles>
|
||||||
|
<activeProfiles>
|
||||||
|
<activeProfile>setup-java-gpg</activeProfile>
|
||||||
|
</activeProfiles>
|
||||||
|
</settings>`;
|
||||||
|
|
||||||
|
expect(auth.generate(id, username, password, gpgPassphrase)).toEqual(
|
||||||
|
expectedSettings
|
||||||
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('does not add a gpg profile when the passphrase env var is the maven-gpg-plugin default', () => {
|
||||||
|
const id = 'packages';
|
||||||
|
const username = 'USER';
|
||||||
|
const password = '&<>"\'\'"><&';
|
||||||
|
const gpgPassphrase = 'MAVEN_GPG_PASSPHRASE';
|
||||||
|
|
||||||
|
const expectedSettings = `<settings xmlns="http://maven.apache.org/SETTINGS/1.0.0"
|
||||||
|
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
||||||
|
xsi:schemaLocation="http://maven.apache.org/SETTINGS/1.0.0 https://maven.apache.org/xsd/settings-1.0.0.xsd">
|
||||||
|
<interactiveMode>false</interactiveMode>
|
||||||
|
<servers>
|
||||||
<server>
|
<server>
|
||||||
<id>gpg.passphrase</id>
|
<id>${id}</id>
|
||||||
<passphrase>\${env.${gpgPassphrase}}</passphrase>
|
<username>\${env.${username}}</username>
|
||||||
|
<password>\${env.&<>"''"><&}</password>
|
||||||
</server>
|
</server>
|
||||||
</servers>
|
</servers>
|
||||||
</settings>`;
|
</settings>`;
|
||||||
|
|||||||
6
dist/cleanup/index.js
vendored
6
dist/cleanup/index.js
vendored
@ -95849,6 +95849,12 @@ const INPUT_GPG_PRIVATE_KEY = 'gpg-private-key';
|
|||||||
const INPUT_GPG_PASSPHRASE = 'gpg-passphrase';
|
const INPUT_GPG_PASSPHRASE = 'gpg-passphrase';
|
||||||
const INPUT_DEFAULT_GPG_PRIVATE_KEY = (/* unused pure expression or super */ null && (undefined));
|
const INPUT_DEFAULT_GPG_PRIVATE_KEY = (/* unused pure expression or super */ null && (undefined));
|
||||||
const INPUT_DEFAULT_GPG_PASSPHRASE = 'GPG_PASSPHRASE';
|
const INPUT_DEFAULT_GPG_PASSPHRASE = 'GPG_PASSPHRASE';
|
||||||
|
// The default name of the environment variable the maven-gpg-plugin reads the
|
||||||
|
// passphrase from (property `gpg.passphraseEnvName`). When the configured
|
||||||
|
// passphrase env var name matches this, no extra configuration is required.
|
||||||
|
const MAVEN_GPG_PASSPHRASE_DEFAULT_ENV = 'MAVEN_GPG_PASSPHRASE';
|
||||||
|
// Id of the settings.xml profile used to set `gpg.passphraseEnvName`.
|
||||||
|
const GPG_PASSPHRASE_PROFILE_ID = 'setup-java-gpg';
|
||||||
const INPUT_CACHE = 'cache';
|
const INPUT_CACHE = 'cache';
|
||||||
const INPUT_CACHE_DEPENDENCY_PATH = 'cache-dependency-path';
|
const INPUT_CACHE_DEPENDENCY_PATH = 'cache-dependency-path';
|
||||||
const INPUT_JOB_STATUS = 'job-status';
|
const INPUT_JOB_STATUS = 'job-status';
|
||||||
|
|||||||
29
dist/setup/index.js
vendored
29
dist/setup/index.js
vendored
@ -73294,6 +73294,12 @@ const INPUT_GPG_PRIVATE_KEY = 'gpg-private-key';
|
|||||||
const INPUT_GPG_PASSPHRASE = 'gpg-passphrase';
|
const INPUT_GPG_PASSPHRASE = 'gpg-passphrase';
|
||||||
const INPUT_DEFAULT_GPG_PRIVATE_KEY = undefined;
|
const INPUT_DEFAULT_GPG_PRIVATE_KEY = undefined;
|
||||||
const INPUT_DEFAULT_GPG_PASSPHRASE = 'GPG_PASSPHRASE';
|
const INPUT_DEFAULT_GPG_PASSPHRASE = 'GPG_PASSPHRASE';
|
||||||
|
// The default name of the environment variable the maven-gpg-plugin reads the
|
||||||
|
// passphrase from (property `gpg.passphraseEnvName`). When the configured
|
||||||
|
// passphrase env var name matches this, no extra configuration is required.
|
||||||
|
const MAVEN_GPG_PASSPHRASE_DEFAULT_ENV = 'MAVEN_GPG_PASSPHRASE';
|
||||||
|
// Id of the settings.xml profile used to set `gpg.passphraseEnvName`.
|
||||||
|
const GPG_PASSPHRASE_PROFILE_ID = 'setup-java-gpg';
|
||||||
const INPUT_CACHE = 'cache';
|
const INPUT_CACHE = 'cache';
|
||||||
const INPUT_CACHE_DEPENDENCY_PATH = 'cache-dependency-path';
|
const INPUT_CACHE_DEPENDENCY_PATH = 'cache-dependency-path';
|
||||||
const constants_INPUT_JOB_STATUS = 'job-status';
|
const constants_INPUT_JOB_STATUS = 'job-status';
|
||||||
@ -127311,12 +127317,25 @@ function generate(id, username, password, gpgPassphrase) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
if (gpgPassphrase) {
|
// The maven-gpg-plugin reads the passphrase from the environment variable
|
||||||
const gpgServer = {
|
// named by the `gpg.passphraseEnvName` property (default MAVEN_GPG_PASSPHRASE).
|
||||||
id: 'gpg.passphrase',
|
// Only configure it when the requested env var name differs from that default;
|
||||||
passphrase: `\${env.${gpgPassphrase}}`
|
// otherwise the plugin already reads the right variable and no extra settings
|
||||||
|
// are needed. Writing `gpg.passphrase` to settings.xml is deprecated and fails
|
||||||
|
// when the plugin's `bestPractices` mode is enabled.
|
||||||
|
if (gpgPassphrase &&
|
||||||
|
gpgPassphrase !== MAVEN_GPG_PASSPHRASE_DEFAULT_ENV) {
|
||||||
|
xmlObj.settings.profiles = {
|
||||||
|
profile: {
|
||||||
|
id: GPG_PASSPHRASE_PROFILE_ID,
|
||||||
|
properties: {
|
||||||
|
'gpg.passphraseEnvName': gpgPassphrase
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
xmlObj.settings.activeProfiles = {
|
||||||
|
activeProfile: GPG_PASSPHRASE_PROFILE_ID
|
||||||
};
|
};
|
||||||
xmlObj.settings.servers.server.push(gpgServer);
|
|
||||||
}
|
}
|
||||||
return (0,lib/* create */.vt)(xmlObj).end({
|
return (0,lib/* create */.vt)(xmlObj).end({
|
||||||
headless: true,
|
headless: true,
|
||||||
|
|||||||
@ -682,15 +682,27 @@ If you use `maven-gpg-plugin` older than 3.2.0, or you prefer signing with the `
|
|||||||
MAVEN_GPG_PASSPHRASE: ${{ secrets.MAVEN_GPG_PASSPHRASE }}
|
MAVEN_GPG_PASSPHRASE: ${{ secrets.MAVEN_GPG_PASSPHRASE }}
|
||||||
```
|
```
|
||||||
|
|
||||||
With these inputs, setup-java adds a `gpg.passphrase` server to the generated `settings.xml`:
|
The `gpg-passphrase` input is the **name of the environment variable** that holds the passphrase (not the passphrase itself). The [Maven GPG Plugin](https://maven.apache.org/plugins/maven-gpg-plugin/) reads the passphrase from the environment variable named by its `gpg.passphraseEnvName` property, which defaults to `MAVEN_GPG_PASSPHRASE`.
|
||||||
|
|
||||||
|
- If `gpg-passphrase` is `MAVEN_GPG_PASSPHRASE`, the plugin already reads that variable by default, so setup-java writes nothing extra to `settings.xml`.
|
||||||
|
- If `gpg-passphrase` is any other name, setup-java configures `gpg.passphraseEnvName` through an active profile in the generated `settings.xml` so the plugin reads the passphrase from that variable:
|
||||||
|
|
||||||
```xml
|
```xml
|
||||||
<server>
|
<profiles>
|
||||||
<id>gpg.passphrase</id>
|
<profile>
|
||||||
<passphrase>${env.MAVEN_GPG_PASSPHRASE}</passphrase>
|
<id>setup-java-gpg</id>
|
||||||
</server>
|
<properties>
|
||||||
|
<gpg.passphraseEnvName>GPG_PASSPHRASE</gpg.passphraseEnvName>
|
||||||
|
</properties>
|
||||||
|
</profile>
|
||||||
|
</profiles>
|
||||||
|
<activeProfiles>
|
||||||
|
<activeProfile>setup-java-gpg</activeProfile>
|
||||||
|
</activeProfiles>
|
||||||
```
|
```
|
||||||
|
|
||||||
|
> **Note:** Earlier versions of setup-java wrote a `gpg.passphrase` server to `settings.xml`. That mechanism is deprecated by the Maven GPG Plugin and fails when its `bestPractices` mode is enabled, so setup-java now relies on `gpg.passphraseEnvName` instead.
|
||||||
|
|
||||||
When signing with the `gpg` executable, the Maven GPG Plugin configuration in your `pom.xml` should contain the following structure to avoid possible issues like `Inappropriate ioctl for device` or `gpg: signing failed: No such file or directory`:
|
When signing with the `gpg` executable, the Maven GPG Plugin configuration in your `pom.xml` should contain the following structure to avoid possible issues like `Inappropriate ioctl for device` or `gpg: signing failed: No such file or directory`:
|
||||||
|
|
||||||
```xml
|
```xml
|
||||||
@ -703,7 +715,7 @@ When signing with the `gpg` executable, the Maven GPG Plugin configuration in yo
|
|||||||
</configuration>
|
</configuration>
|
||||||
```
|
```
|
||||||
|
|
||||||
GPG 2.1 requires `--pinentry-mode` to be set to `loopback` in order to pick up the `gpg.passphrase` value defined in Maven `settings.xml`.
|
GPG 2.1 requires `--pinentry-mode` to be set to `loopback` in order to read the passphrase non-interactively.
|
||||||
|
|
||||||
***NOTE***: If, when using the default `gpg` signer, the error `gpg: Sorry, no terminal at all requested - can't get input` [is encountered](https://github.com/actions/setup-java/issues/554), please update the version of `maven-gpg-plugin` to 1.6 or higher.
|
***NOTE***: If, when using the default `gpg` signer, the error `gpg: Sorry, no terminal at all requested - can't get input` [is encountered](https://github.com/actions/setup-java/issues/554), please update the version of `maven-gpg-plugin` to 1.6 or higher.
|
||||||
|
|
||||||
|
|||||||
25
src/auth.ts
25
src/auth.ts
@ -93,12 +93,27 @@ export function generate(
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
if (gpgPassphrase) {
|
// The maven-gpg-plugin reads the passphrase from the environment variable
|
||||||
const gpgServer = {
|
// named by the `gpg.passphraseEnvName` property (default MAVEN_GPG_PASSPHRASE).
|
||||||
id: 'gpg.passphrase',
|
// Only configure it when the requested env var name differs from that default;
|
||||||
passphrase: `\${env.${gpgPassphrase}}`
|
// otherwise the plugin already reads the right variable and no extra settings
|
||||||
|
// are needed. Writing `gpg.passphrase` to settings.xml is deprecated and fails
|
||||||
|
// when the plugin's `bestPractices` mode is enabled.
|
||||||
|
if (
|
||||||
|
gpgPassphrase &&
|
||||||
|
gpgPassphrase !== constants.MAVEN_GPG_PASSPHRASE_DEFAULT_ENV
|
||||||
|
) {
|
||||||
|
xmlObj.settings.profiles = {
|
||||||
|
profile: {
|
||||||
|
id: constants.GPG_PASSPHRASE_PROFILE_ID,
|
||||||
|
properties: {
|
||||||
|
'gpg.passphraseEnvName': gpgPassphrase
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
xmlObj.settings.activeProfiles = {
|
||||||
|
activeProfile: constants.GPG_PASSPHRASE_PROFILE_ID
|
||||||
};
|
};
|
||||||
xmlObj.settings.servers.server.push(gpgServer);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return xmlCreate(xmlObj).end({
|
return xmlCreate(xmlObj).end({
|
||||||
|
|||||||
@ -21,6 +21,14 @@ export const INPUT_GPG_PASSPHRASE = 'gpg-passphrase';
|
|||||||
export const INPUT_DEFAULT_GPG_PRIVATE_KEY = undefined;
|
export const INPUT_DEFAULT_GPG_PRIVATE_KEY = undefined;
|
||||||
export const INPUT_DEFAULT_GPG_PASSPHRASE = 'GPG_PASSPHRASE';
|
export const INPUT_DEFAULT_GPG_PASSPHRASE = 'GPG_PASSPHRASE';
|
||||||
|
|
||||||
|
// The default name of the environment variable the maven-gpg-plugin reads the
|
||||||
|
// passphrase from (property `gpg.passphraseEnvName`). When the configured
|
||||||
|
// passphrase env var name matches this, no extra configuration is required.
|
||||||
|
export const MAVEN_GPG_PASSPHRASE_DEFAULT_ENV = 'MAVEN_GPG_PASSPHRASE';
|
||||||
|
|
||||||
|
// Id of the settings.xml profile used to set `gpg.passphraseEnvName`.
|
||||||
|
export const GPG_PASSPHRASE_PROFILE_ID = 'setup-java-gpg';
|
||||||
|
|
||||||
export const INPUT_CACHE = 'cache';
|
export const INPUT_CACHE = 'cache';
|
||||||
export const INPUT_CACHE_DEPENDENCY_PATH = 'cache-dependency-path';
|
export const INPUT_CACHE_DEPENDENCY_PATH = 'cache-dependency-path';
|
||||||
export const INPUT_JOB_STATUS = 'job-status';
|
export const INPUT_JOB_STATUS = 'job-status';
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user