|
| 1 | +# Publishing the Java SDK |
| 2 | + |
| 3 | +The Java SDK is released from GitHub Actions via a single **Release** workflow |
| 4 | +([`.github/workflows/release.yml`](.github/workflows/release.yml)). There is no local release script |
| 5 | +and no separate tag-triggered publish workflow — one manual run drives the whole pipeline. Do not |
| 6 | +publish from your local machine. |
| 7 | + |
| 8 | +Java releases are **stable-only**: the workflow validates that `version` matches `vX.Y.Z` and rejects |
| 9 | +prerelease or `-SNAPSHOT` versions. The entire job runs in the protected **`release`** GitHub |
| 10 | +Environment, which holds the Sonatype / GPG secrets and **requires reviewer approval** before any tag |
| 11 | +is pushed or any artifact is published. |
| 12 | + |
| 13 | +## Release |
| 14 | + |
| 15 | +1. Open a PR that bumps the version and merge it to `main`. |
| 16 | +2. Copy the full 40-character SHA of the commit you want to release (use GitHub's **Copy full SHA** |
| 17 | + button). |
| 18 | +3. Run the **Release** workflow (Actions → Release → Run workflow) with: |
| 19 | + - `version` — the release version, e.g. `v1.2.3`. |
| 20 | + - `sha` — the full 40-char commit SHA to tag. Supplying an explicit SHA (not a branch) ensures |
| 21 | + commits that land on `main` during the approval gate are **not** silently included. |
| 22 | +4. Approve the `release` environment when GitHub prompts. |
| 23 | + |
| 24 | +Once approved, the workflow: |
| 25 | + |
| 26 | +1. Validates the version and SHA, and verifies the SHA is an ancestor of `origin/main`. |
| 27 | +2. Runs `./gradlew check` on the chosen SHA. |
| 28 | +3. Creates and pushes the annotated tag `vX.Y.Z` at that SHA, then re-runs `./gradlew check` at the tag. |
| 29 | +4. Builds the release artifacts. |
| 30 | +5. Creates the GitHub Release and uploads the SDK jars (main / sources / javadoc), the |
| 31 | + `braintrust-java-agent` jar, and the `braintrust-otel-extension` jar. |
| 32 | +6. Publishes to Maven Central via Sonatype, GPG-signed with the project key. |
| 33 | +7. Polls Maven Central until the new version is visible. **This can take many hours.** |
| 34 | + |
| 35 | +## Re-publishing a failed release |
| 36 | + |
| 37 | +Re-run the **Release** workflow with the **same `version`**. If the tag already exists, the |
| 38 | +tag-creation step is skipped and the rest of the pipeline runs against the existing tag; GitHub |
| 39 | +Release asset uploads clobber any partial uploads. |
| 40 | + |
| 41 | +## Verify |
| 42 | + |
| 43 | +- GitHub Release: https://github.com/braintrustdata/braintrust-sdk-java/releases |
| 44 | +- Maven Central: https://central.sonatype.com/artifact/dev.braintrust/braintrust-sdk-java/versions |
| 45 | + |
| 46 | +Then run the test app with the newly published SDK (check that traces and evals look okay): |
| 47 | + |
| 48 | +- https://github.com/braintrustdata/sdk-test-apps — `make verify-java` |
0 commit comments