You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Publish reference-implementations/java as org.tomlschema:tomlschema:1.0.0-rc.2 on Maven Central. The TOML Schema language version remains 1.0.0.
Maintainer setup — required before implementation can publish
Use the agreed coordinate org.tomlschema:tomlschema; org.tomlschema is derived from the canonical tomlschema.org domain.
Sign in to the Central Publisher Portal with the project-maintainer identity and establish the organization/publisher ownership model.
Request namespace org.tomlschema and prove control of tomlschema.org using the exact DNS TXT record Sonatype provides. Keep the record until the portal reports the namespace as verified.
Add at least one backup project maintainer to the Central organization/namespace.
Generate a Central Portal user token for CI; do not use a personal password or legacy OSSRH token.
Create or designate a project OpenPGP signing key, publish its public key to a public keyserver, and record the fingerprint/rotation owner. The private key and passphrase must never enter the repository.
Create a protected GitHub environment named maven-central, restrict it to java-v* tags, require maintainer review where supported, and add environment secrets for the Central token and signing key/passphrase.
Decide whether the first deployment should be USER_MANAGED in the Central Portal (recommended for rc.2) or automatically published after validation.
Repository implementation — after setup is confirmed
Change the POM artifactId from toml-schema to tomlschema; keep Java package org.tomlschema.
Complete reference-implementations/java/pom.xml with Central-required metadata: project URL, MIT license, developers/organization, and SCM connection/developer connection/URL.
Attach source and Javadoc JARs and configure reproducible release output.
Add release-only signing and a current Central Publisher Portal-compatible Maven publishing plugin/profile. Do not copy a legacy oss.sonatype.org workflow.
Ensure the published POM preserves the org.tomlj:tomlj runtime dependency and excludes test dependencies.
Add a version/tag guard: java-v1.0.0-rc.2 must match the POM artifact version.
Add .github/workflows/release-java.yml triggered only by java-v* tags plus a safe manual dry-run mode. It must use the maven-central environment, minimal contents: read permission, Java 25, the normal test suite, package validation, signing, upload, and status polling/failure reporting.
Upload the unsigned/locally built release bundle as a GitHub Actions artifact before the protected publish job so maintainers can inspect its file list and POM.
Update the Java README and REFERENCE_IMPLEMENTATIONS.md with the Maven dependency snippet, Central URL, artifact-vs-language version explanation, and tag convention.
Execution plan
Run mvn -B -f reference-implementations/java/pom.xml test.
Build the release artifacts without publishing; verify the main, sources, and Javadoc JARs, POM metadata, checksums/signatures generated for upload, and absence of test classes or secrets.
Merge the workflow and metadata, then create java-v1.0.0-rc.2 from the reviewed commit.
Approve the protected job and upload as a user-managed deployment for the first release.
Inspect Central validation, then explicitly publish the validated deployment.
From a clean temporary Maven project, resolve org.tomlschema:tomlschema:1.0.0-rc.2, compile the documented API example, and confirm source/Javadoc attachment resolution.
Confirm Central displays the expected license, SCM, owners, and project links before marking complete.
Acceptance criteria
org.tomlschema:tomlschema:1.0.0-rc.2 resolves from Maven Central.
Main, sources, Javadoc, POM, signatures, and required checksums pass Central validation.
Publishing is tag-gated, approval-protected, repeatable, and uses no legacy endpoint or personal password.
Clean-consumer smoke test and documentation updates are complete.
Parent: #129
Publish
reference-implementations/javaasorg.tomlschema:tomlschema:1.0.0-rc.2on Maven Central. The TOML Schema language version remains1.0.0.Maintainer setup — required before implementation can publish
org.tomlschema:tomlschema;org.tomlschemais derived from the canonicaltomlschema.orgdomain.org.tomlschemaand prove control oftomlschema.orgusing the exact DNS TXT record Sonatype provides. Keep the record until the portal reports the namespace as verified.maven-central, restrict it tojava-v*tags, require maintainer review where supported, and add environment secrets for the Central token and signing key/passphrase.USER_MANAGEDin the Central Portal (recommended forrc.2) or automatically published after validation.Repository implementation — after setup is confirmed
artifactIdfromtoml-schematotomlschema; keep Java packageorg.tomlschema.reference-implementations/java/pom.xmlwith Central-required metadata: project URL, MIT license, developers/organization, and SCM connection/developer connection/URL.oss.sonatype.orgworkflow.org.tomlj:tomljruntime dependency and excludes test dependencies.java-v1.0.0-rc.2must match the POM artifact version..github/workflows/release-java.ymltriggered only byjava-v*tags plus a safe manual dry-run mode. It must use themaven-centralenvironment, minimalcontents: readpermission, Java 25, the normal test suite, package validation, signing, upload, and status polling/failure reporting.REFERENCE_IMPLEMENTATIONS.mdwith the Maven dependency snippet, Central URL, artifact-vs-language version explanation, and tag convention.Execution plan
mvn -B -f reference-implementations/java/pom.xml test.java-v1.0.0-rc.2from the reviewed commit.org.tomlschema:tomlschema:1.0.0-rc.2, compile the documented API example, and confirm source/Javadoc attachment resolution.Acceptance criteria
org.tomlschema:tomlschema:1.0.0-rc.2resolves from Maven Central.References: namespace registration, Central requirements, Publisher API.