Skip to content

Commit 2b44447

Browse files
authored
Merge pull request #154 from braintrustdata/docs/publishing-md
Add PUBLISHING.md
2 parents f2f4db1 + 72d543f commit 2b44447

1 file changed

Lines changed: 48 additions & 0 deletions

File tree

‎PUBLISHING.md‎

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
# Publishing the Java SDK
2+
3+
The Java SDK is released from GitHub Actions via a single **Release** workflow
4+
([`.github/workflows/release.yml`](.github/workflows/release.yml)). There is no local release script
5+
and no separate tag-triggered publish workflow — one manual run drives the whole pipeline. Do not
6+
publish from your local machine.
7+
8+
Java releases are **stable-only**: the workflow validates that `version` matches `vX.Y.Z` and rejects
9+
prerelease or `-SNAPSHOT` versions. The entire job runs in the protected **`release`** GitHub
10+
Environment, which holds the Sonatype / GPG secrets and **requires reviewer approval** before any tag
11+
is pushed or any artifact is published.
12+
13+
## Release
14+
15+
1. Open a PR that bumps the version and merge it to `main`.
16+
2. Copy the full 40-character SHA of the commit you want to release (use GitHub's **Copy full SHA**
17+
button).
18+
3. Run the **Release** workflow (Actions → Release → Run workflow) with:
19+
- `version` — the release version, e.g. `v1.2.3`.
20+
- `sha` — the full 40-char commit SHA to tag. Supplying an explicit SHA (not a branch) ensures
21+
commits that land on `main` during the approval gate are **not** silently included.
22+
4. Approve the `release` environment when GitHub prompts.
23+
24+
Once approved, the workflow:
25+
26+
1. Validates the version and SHA, and verifies the SHA is an ancestor of `origin/main`.
27+
2. Runs `./gradlew check` on the chosen SHA.
28+
3. Creates and pushes the annotated tag `vX.Y.Z` at that SHA, then re-runs `./gradlew check` at the tag.
29+
4. Builds the release artifacts.
30+
5. Creates the GitHub Release and uploads the SDK jars (main / sources / javadoc), the
31+
`braintrust-java-agent` jar, and the `braintrust-otel-extension` jar.
32+
6. Publishes to Maven Central via Sonatype, GPG-signed with the project key.
33+
7. Polls Maven Central until the new version is visible. **This can take many hours.**
34+
35+
## Re-publishing a failed release
36+
37+
Re-run the **Release** workflow with the **same `version`**. If the tag already exists, the
38+
tag-creation step is skipped and the rest of the pipeline runs against the existing tag; GitHub
39+
Release asset uploads clobber any partial uploads.
40+
41+
## Verify
42+
43+
- GitHub Release: https://github.com/braintrustdata/braintrust-sdk-java/releases
44+
- Maven Central: https://central.sonatype.com/artifact/dev.braintrust/braintrust-sdk-java/versions
45+
46+
Then run the test app with the newly published SDK (check that traces and evals look okay):
47+
48+
- https://github.com/braintrustdata/sdk-test-apps — `make verify-java`

0 commit comments

Comments
 (0)