Repository navigation
feat(PAY-919): publish bank-link SDK to GitHub Packages on release - #3
Conversation
Adds a release-triggered GitHub Actions workflow that publishes the :bank-link AAR to maven.pkg.github.com using the auto-provisioned GITHUB_TOKEN, and wires the publication version to the release tag so each tag publishes a distinct artifact instead of overwriting 0.1.0. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
📝 WalkthroughWalkthroughA new GitHub Actions workflow publishes the ChangesRelease Publish Pipeline
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/publish.yml:
- Around line 22-35: The workflow is using mutable version tags (like `@v4`) for
GitHub Actions which are vulnerable to tag reassignment attacks. Replace the
version tags with immutable commit SHAs for the three actions: actions/checkout,
actions/setup-java, and gradle/actions/setup-gradle. Update each uses statement
to reference the specific commit SHA instead of the version tag, and add the
version tag as a comment for clarity (e.g., uses:
actions/checkout@<full_commit_sha> # v4). Use the commit SHAs provided in the
review comment for each action to ensure security and immutability.
In `@bank-link/build.gradle.kts`:
- Line 16: The version property assignment uses an unsafe cast that throws
ClassCastException if the property is a non-String value instead of gracefully
returning null. Change the cast operator in the version assignment from `as
String?` to `as? String` to use the safe cast operator, which will return null
if findProperty("versionName") is not a String value, allowing the Elvis
operator to provide the default fallback value "0.1.0-SNAPSHOT" safely.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: 595d95cf-5f76-44c6-a24a-80eaf1cde03d
📒 Files selected for processing (2)
.github/workflows/publish.ymlbank-link/build.gradle.kts
Summary
.github/workflows/publish.ymltriggered onrelease: [published]. Runs./gradlew :bank-link:publishon JDK 17 with the auto-provisionedGITHUB_TOKEN, matching the conventions inci.yml(persist-credentials off, gradle/actions/setup-gradle@v4, concurrency,--no-daemon --stacktrace).bank-link/build.gradle.ktsto read its version from theversionNameGradle property (stripping a leadingv), so each release tag publishes a distinct artifact instead of overwriting the hardcoded0.1.0. Local builds fall back to0.1.0-SNAPSHOT.Linear: PAY-919
Test plan
0.1.1(orv0.1.1)Publish to GitHub Packagesworkflow run succeedscom.grailpay:bank-link:0.1.1appears under the repo's Packages tab with AAR + sources + javadoc🤖 Generated with Claude Code
Summary by CodeRabbit