Repository navigation
build: add Kotlin task for OIDC-authenticated Maven publishing - #1158
jbeckwith-oai wants to merge 7 commits into
Conversation
Castiron custom codeEvaluated main: ✅ No new custom-code files detected. 105 mixed files remain; 0 existing customizations changed. Compared 105 existing customizations unchanged
65 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 37981792071 --repo openai/openai-java \
--name castiron-custom-code-37981792071-1 --dir /tmp/castiron-custom-code-37981792071-1
git apply --stat /tmp/castiron-custom-code-37981792071-1/custom-code.patch
cat /tmp/castiron-custom-code-37981792071-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin a22dd21ba519a6458881d8e7274fb431639d9755 ec8b428b0c516ce622e512af893e0dc5b9f34c5e
python3 scripts/castiron/custom_code_report.py report \
--base a22dd21ba519a6458881d8e7274fb431639d9755 \
--head ec8b428b0c516ce622e512af893e0dc5b9f34c5e --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-ec8b428b0c51
cat /tmp/castiron-custom-code-ec8b428b0c51/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
markstuart-oai
left a comment
There was a problem hiding this comment.
Reviewed 5d31a9700fa16320d81aa83bffb0a48db7bbcffd. No actionable findings in the opt-in publishing-proxy path.
Proxy steps exclude Sonatype credentials, preserve release-source and attestation checks, and verify signed staging output before upload. The helper refuses redirects and avoids replaying an uncertain upload. The direct path remains available with its existing credentials. This was source-only review; I did not run tests, publish artifacts, or verify a live proxy deployment.
dpiet-oai
left a comment
There was a problem hiding this comment.
Reviewed the build and publishing integration at 5d31a9700fa16320d81aa83bffb0a48db7bbcffd. I would ask for a design revision around publishing ownership and test integration before enabling this path.
Python itself is not the issue: this repository already has Python tooling. The signed file repository and stageForAuthProxy property are reasonable Gradle patterns. The concern is maintaining a second publishing implementation and a separate test entry point. Specific comments are inline.
One important constraint: the pinned Vanniktech 0.34.0 plugin hardcodes Sonatype's URL and constructs its bearer token from username/password. Using it through this proxy would require an adapter or plugin change, not just a repository URL override: https://github.com/vanniktech/gradle-maven-publish-plugin/blob/0.34.0/plugin/src/main/kotlin/com/vanniktech/maven/publish/central/MavenCentralBuildService.kt#L36
Validation: all 13 Python tests passed locally, and current PR CI checks are green. I did not run the full Gradle suite or publish artifacts. These are design and maintainability concerns; this review does not claim a demonstrated production failure.
Add an opt-in Maven publishing proxy path implemented entirely in the repository's Kotlin build logic. The shared release step signs once and either publishes directly or stages for the proxy. Setting
MAVEN_CENTRAL_AUTH_PROXY_URLselects proxy publishing and suppresses Sonatype credentials on the runner; leaving it unset preserves direct publishing.publishViaAuthProxyobtains a GitHub OIDC assertion, exchanges it for an Entra token, derives its expected inventory from Gradle MavenPublication configuration and verifies staged signatures/checksums and attested JAR hashes, streams one upload, records the bundle digest/deployment ID, and validates/publishes the deployment. The uploader JVM disables transport retries before startup; redirects and upload fallback are disabled. Tests run through the existing:buildSrc:testsuite.No Azure login action or CLI dependency, extra publishing framework, Python publisher, or experimental lab files are included. Entra remains the identity provider; authentication and publication code are maintained here by explicit owner decision.
Validation:
Publication coordinates, classifiers, extensions, and binary source paths now come from the finalized MavenPublication model. A regression test exercises custom coordinates and a ZIP classifier, including rejection of missing declared files; existing tampering and signature checks remain.
Rollout: disabled by default. Owner review, federation/proxy provisioning, and a nonpublishing live canary are required before configuring the URL. No secrets or infrastructure were changed. Keep this PR draft pending remaining review and integration validation.