Skip to content

feat(PAY-919): publish bank-link SDK to GitHub Packages on release - #3

Merged
tomschlick merged 1 commit into
masterfrom
tomschlick/publish-package-github-action
Jun 22, 2026
Merged

tomschlick merged 1 commit into
masterfrom
tomschlick/publish-package-github-action

Conversation

@tomschlick

@tomschlick tomschlick commented Jun 22, 2026 •

Copy link
Copy Markdown
Member

Summary

  • New .github/workflows/publish.yml triggered on release: [published]. Runs ./gradlew :bank-link:publish on JDK 17 with the auto-provisioned GITHUB_TOKEN, matching the conventions in ci.yml (persist-credentials off, gradle/actions/setup-gradle@v4, concurrency, --no-daemon --stacktrace).
  • Wired bank-link/build.gradle.kts to read its version from the versionName Gradle property (stripping a leading v), so each release tag publishes a distinct artifact instead of overwriting the hardcoded 0.1.0. Local builds fall back to 0.1.0-SNAPSHOT.

Linear: PAY-919

Test plan

  • Merge, then cut a draft GitHub release with a tag like 0.1.1 (or v0.1.1)
  • Confirm the Publish to GitHub Packages workflow run succeeds
  • Confirm com.grailpay:bank-link:0.1.1 appears under the repo's Packages tab with AAR + sources + javadoc

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Implemented automated publishing workflow triggered by GitHub Releases.
    • Updated version management to use release tags for published packages instead of fixed versions.

Adds a release-triggered GitHub Actions workflow that publishes the
:bank-link AAR to maven.pkg.github.com using the auto-provisioned
GITHUB_TOKEN, and wires the publication version to the release tag so
each tag publishes a distinct artifact instead of overwriting 0.1.0.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Jun 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

A new GitHub Actions workflow publishes the bank-link module to GitHub Packages whenever a GitHub Release is created. The build.gradle.kts is updated to read the artifact version from a versionName Gradle property (stripping a leading v, defaulting to 0.1.0-SNAPSHOT), which the workflow supplies from the release tag.

Changes

Release Publish Pipeline

Layer / File(s) Summary
Dynamic artifact versioning
bank-link/build.gradle.kts
Maven publishing version is now derived from the versionName Gradle property with a v-prefix strip and a 0.1.0-SNAPSHOT fallback, replacing the previous hardcoded 0.1.0.
GitHub Actions publish workflow
.github/workflows/publish.yml
New workflow triggered on release: published; configures least-privilege permissions, a concurrency guard, JDK 17, Gradle caching, and a Gradle publish step that passes the release tag as versionName with GITHUB_TOKEN credentials for GitHub Packages.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title 'feat(PAY-919): publish bank-link SDK to GitHub Packages on release' directly and clearly summarizes the main change: automated publishing of the bank-link SDK to GitHub Packages when a release is published.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch tomschlick/publish-package-github-action

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/publish.yml:
- Around line 22-35: The workflow is using mutable version tags (like `@v4`) for
GitHub Actions which are vulnerable to tag reassignment attacks. Replace the
version tags with immutable commit SHAs for the three actions: actions/checkout,
actions/setup-java, and gradle/actions/setup-gradle. Update each uses statement
to reference the specific commit SHA instead of the version tag, and add the
version tag as a comment for clarity (e.g., uses:
actions/checkout@<full_commit_sha> # v4). Use the commit SHAs provided in the
review comment for each action to ensure security and immutability.

In `@bank-link/build.gradle.kts`:
- Line 16: The version property assignment uses an unsafe cast that throws
ClassCastException if the property is a non-String value instead of gracefully
returning null. Change the cast operator in the version assignment from `as
String?` to `as? String` to use the safe cast operator, which will return null
if findProperty("versionName") is not a String value, allowing the Elvis
operator to provide the default fallback value "0.1.0-SNAPSHOT" safely.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 595d95cf-5f76-44c6-a24a-80eaf1cde03d

📥 Commits

Reviewing files that changed from the base of the PR and between 9e66ebf and 088a557.

📒 Files selected for processing (2)
  • .github/workflows/publish.yml
  • bank-link/build.gradle.kts

Comment thread .github/workflows/publish.yml
Comment thread bank-link/build.gradle.kts
@rk111
rk111 self-requested a review June 22, 2026 17:36
@tomschlick
tomschlick merged commit 5fcf0aa into master Jun 22, 2026
2 checks passed
@tomschlick
tomschlick deleted the tomschlick/publish-package-github-action branch June 22, 2026 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants