Skip to content

build: add Kotlin task for OIDC-authenticated Maven publishing - #1158

Draft
jbeckwith-oai wants to merge 7 commits into
mainfrom
codex/sonatype-auth-proxy
Draft

jbeckwith-oai wants to merge 7 commits into
mainfrom
codex/sonatype-auth-proxy

Conversation

@jbeckwith-oai

@jbeckwith-oai jbeckwith-oai commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Add an opt-in Maven publishing proxy path implemented entirely in the repository's Kotlin build logic. The shared release step signs once and either publishes directly or stages for the proxy. Setting MAVEN_CENTRAL_AUTH_PROXY_URL selects proxy publishing and suppresses Sonatype credentials on the runner; leaving it unset preserves direct publishing.

publishViaAuthProxy obtains a GitHub OIDC assertion, exchanges it for an Entra token, derives its expected inventory from Gradle MavenPublication configuration and verifies staged signatures/checksums and attested JAR hashes, streams one upload, records the bundle digest/deployment ID, and validates/publishes the deployment. The uploader JVM disables transport retries before startup; redirects and upload fallback are disabled. Tests run through the existing :buildSrc:test suite.

No Azure login action or CLI dependency, extra publishing framework, Python publisher, or experimental lab files are included. Entra remains the identity provider; authentication and publication code are maintained here by explicit owner decision.

Validation:

  • 32 focused Kotlin publisher and publishing-policy tests pass.
  • Read-only inspection of the actual Gradle model confirms all four publication inventories and binary provenance paths.
  • Two fresh independent review rounds passed for the publication inventory change; diff checks pass.
  • Full CI runs on the new head. No live authentication or publishing was performed.

Publication coordinates, classifiers, extensions, and binary source paths now come from the finalized MavenPublication model. A regression test exercises custom coordinates and a ZIP classifier, including rejection of missing declared files; existing tampering and signature checks remain.

Rollout: disabled by default. Owner review, federation/proxy provisioning, and a nonpublishing live canary are required before configuring the URL. No secrets or infrastructure were changed. Keep this PR draft pending remaining review and integration validation.

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Castiron custom code

Evaluated main: a22dd21ba519a6458881d8e7274fb431639d9755.

✅ No new custom-code files detected.

105 mixed files remain; 0 existing customizations changed.

Compared a22dd21ba519 → ec8b428b0c51. Generated baselines verified.

105 existing customizations unchanged
  • openai-java-core/src/main/kotlin/com/openai/models/audio/AudioResponseFormat.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/environments/EnvironmentCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuth.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuthCreateParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/agents/vaults/credentials/CredentialAuthRotateParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponse.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponseInjectEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponseInjectFailedEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponseStreamEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponseToolSearchOutputItemParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/beta/responses/BetaResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionMessageFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/chat/completions/ChatCompletionToolMessageParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/conversations/ConversationCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/conversations/items/ItemCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/Embedding.kt
  • openai-java-core/src/main/kotlin/com/openai/models/embeddings/EmbeddingCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/live/ResponseItemCreateEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/Response.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseCreateParams.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionToolCall.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseFunctionWebSearch.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseInputItem.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseStreamEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseTextConfig.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponseToolSearchOutputItemParam.kt
  • openai-java-core/src/main/kotlin/com/openai/models/responses/ResponsesServerEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/videos/Video.kt
  • openai-java-core/src/main/kotlin/com/openai/models/webhooks/UnwrapWebhookEvent.kt
  • openai-java-core/src/main/kotlin/com/openai/models/webhooks/WebhookEndpointWithSecret.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/BetaServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ImageServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/ResponseServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/SkillServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/VideoServiceAsyncImpl.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsync.kt
  • openai-java-core/src/main/kotlin/com/openai/services/async/WebhookServiceAsyncImpl.kt

65 more in the full report.

A changed generated baseline means this report cannot reliably identify which handwritten lines changed.

Inspect the custom-code diff

Download the exact patch produced by this run (requires repository access):

gh run download 37981792071 --repo openai/openai-java \
  --name castiron-custom-code-37981792071-1 --dir /tmp/castiron-custom-code-37981792071-1
git apply --stat /tmp/castiron-custom-code-37981792071-1/custom-code.patch
cat /tmp/castiron-custom-code-37981792071-1/custom-code.patch

Or reproduce it from an SDK checkout containing the vendored reporter:

git fetch --no-tags origin a22dd21ba519a6458881d8e7274fb431639d9755 ec8b428b0c516ce622e512af893e0dc5b9f34c5e
python3 scripts/castiron/custom_code_report.py report \
  --base a22dd21ba519a6458881d8e7274fb431639d9755 \
  --head ec8b428b0c516ce622e512af893e0dc5b9f34c5e --fetch --require-head-hash --public \
  --out /tmp/castiron-custom-code-ec8b428b0c51
cat /tmp/castiron-custom-code-ec8b428b0c51/custom-code.patch

This is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR.

Full report and patch

@markstuart-oai markstuart-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 5d31a9700fa16320d81aa83bffb0a48db7bbcffd. No actionable findings in the opt-in publishing-proxy path.

Proxy steps exclude Sonatype credentials, preserve release-source and attestation checks, and verify signed staging output before upload. The helper refuses redirects and avoids replaying an uncertain upload. The direct path remains available with its existing credentials. This was source-only review; I did not run tests, publish artifacts, or verify a live proxy deployment.

@dpiet-oai dpiet-oai left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the build and publishing integration at 5d31a9700fa16320d81aa83bffb0a48db7bbcffd. I would ask for a design revision around publishing ownership and test integration before enabling this path.

Python itself is not the issue: this repository already has Python tooling. The signed file repository and stageForAuthProxy property are reasonable Gradle patterns. The concern is maintaining a second publishing implementation and a separate test entry point. Specific comments are inline.

One important constraint: the pinned Vanniktech 0.34.0 plugin hardcodes Sonatype's URL and constructs its bearer token from username/password. Using it through this proxy would require an adapter or plugin change, not just a repository URL override: https://github.com/vanniktech/gradle-maven-publish-plugin/blob/0.34.0/plugin/src/main/kotlin/com/vanniktech/maven/publish/central/MavenCentralBuildService.kt#L36

Validation: all 13 Python tests passed locally, and current PR CI checks are green. I did not run the full Gradle suite or publish artifacts. These are design and maintainability concerns; this review does not claim a demonstrated production failure.

Comment thread .github/scripts/publish-maven-central.py Outdated
Comment thread .github/scripts/publish-maven-central.py Outdated
Comment thread .github/workflows/ci.yml Outdated
Comment thread .github/scripts/test_publish_maven_central.py Outdated
@jbeckwith-oai jbeckwith-oai changed the title build: support OIDC-authenticated Maven publishing proxy build: add Kotlin task for OIDC-authenticated Maven publishing Oct 9, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants