Artifacts are published to Maven Central through the Sonatype Central Portal. Once published they're consumable by both Maven and Gradle users — there is no separate "Gradle registry".
The pom.xml is already wired for this: it produces -sources.jar and
-javadoc.jar, GPG-signs everything (the sign-artifacts profile), and uploads via the
central-publishing-maven-plugin with autoPublish=false (uploads a reviewable draft
you release from the Portal UI).
- Central Portal account — sign in at https://central.sonatype.com (GitHub login works).
- Verify the
ai.cleanlistnamespace — Portal → Namespaces → addai.cleanlist. You'll be given a TXT record to add to thecleanlist.aiDNS zone; verification is automatic once it propagates. This is required before anyai.cleanlist.*artifact can be published. - Generate a user token — Portal → Account → Generate User Token. Yields a username/password pair.
- GPG signing key — Central requires signed artifacts:
gpg --batch --gen-key # name it, e.g., "Cleanlist <sal@cleanlist.ai>" gpg --list-secret-keys --keyid-format=long # note the KEYID gpg --keyserver hkps://keys.openpgp.org --send-keys <KEYID>
Never commit this — it lives in your home directory:
<settings>
<servers>
<server>
<id>central</id> <!-- matches publishingServerId in pom.xml -->
<username>CENTRAL_TOKEN_USERNAME</username>
<password>CENTRAL_TOKEN_PASSWORD</password>
</server>
</servers>
</settings>If your GPG key has a passphrase, also add a profile setting <gpg.passphrase>…</gpg.passphrase>
(the pom already passes --pinentry-mode loopback for non-interactive signing).
# JDK 17+ recommended
mvn -Psign-artifacts -DskipTests -Dmaven.javadoc.failOnError=false clean deployThis signs and uploads a draft deployment. Open the
Portal → Deployments, review it, and
click Publish. (Set autoPublish=true in the pom's central plugin to skip the manual
click once you're confident.)
- Bump
<version>inpom.xml(andpackageVersionwhen regenerating — seescripts/generate.sh). mvn -Psign-artifacts -DskipTests -Dmaven.javadoc.failOnError=false clean deploy- Publish the draft in the Portal.
- Tag it:
git tag v<version> && git push --tags.
Maven Central is immutable — a version can never be overwritten or deleted once published. Double-check the draft before releasing.
.github/workflows/release.yml publishes automatically on a v* tag. Add these repo
secrets: CENTRAL_TOKEN_USERNAME, CENTRAL_TOKEN_PASSWORD, GPG_PRIVATE_KEY (armored),
and GPG_PASSPHRASE (empty if the key has none).