Skip to content

chore(release): bump nova-spring-boot-parent to 1.0.0 + add manual publish workflow#2

Merged
ahincho merged 7 commits into
mainfrom
feature/nova-semver-19-20-21-activate-workflows
Jul 21, 2026
Merged

chore(release): bump nova-spring-boot-parent to 1.0.0 + add manual publish workflow#2
ahincho merged 7 commits into
mainfrom
feature/nova-semver-19-20-21-activate-workflows

Conversation

@ahincho

@ahincho ahincho commented Jul 21, 2026

Copy link
Copy Markdown
Owner

Manually bumps the parent POM to 1.0.0 so consumers (ms-course, ms-forum, etc.) can resolve it via Maven. Adds .github/workflows/publish.yml\ (workflow_dispatch) reusing the same pattern as nova-bom. No code change.

ahincho added 7 commits July 12, 2026 13:09
…OVA-SEMVER-19/20/21)

This repo had no CI workflow at all. Adds ci.yml invoking:
- reusable-build-maven.yml
- reusable-build-matrix.yml (Java 21+25)
- reusable-owasp-check.yml (continue-on-error until NVD_API_KEY is
  configured)
- reusable-sbom.yml

Also fixes the distributionManagement URL: it still had the literal
'OWNER' placeholder instead of 'ahincho' (NOVA-SEMVER-00c fixed this
for the 10 Gradle repos with maven-publish, but missed this Maven repo's
distributionManagement block).
'continue-on-error' is not a supported keyword for a job that calls a
reusable workflow via 'uses:' - it broke workflow file parsing entirely.
Moved the actual fix to nova-devops (step-level, in the reusable
workflow itself).
….0.0

Both pe.edu.nova.java:nova-spring-boot-bom and
pe.edu.nova.java.starters:nova-spring-boot-starter are published at
1.0.0 in GitHub Packages (never at 0.1.0-SNAPSHOT). The stale
SNAPSHOT reference made the parent POM unresolvable, failing the
build/matrix/sbom CI jobs with 'Non-resolvable import POM'.

Documented as bug C in
docs/java/06-semantic-versioning-en-java.md §11.9.30.
nova-spring-boot-bom (imported via dependencyManagement) is published
from the separate nova-bom repo, and nova-spring-boot-starter (a plain
dependency) from nova-java-spring-boot-starter. GitHub Packages requires
auth even for public reads, and each repo's Maven registry is scoped to
that repo's own URL - Maven has no way to find either artifact without
an explicit <repositories> entry pointing at the right repo.

Both entries share the 'nova-packages-read' id since they use the same
credentials (see nova-devops' nova-setup-java composite action, which
writes the matching <server> entry in settings.xml from the new
NOVA_PACKAGES_READ_TOKEN secret).

This repo's own dependencyManagement/dependencies declarations are
inherited by every child project via this parent POM, so this also
fixes cross-repo resolution for any project generated from
nova-java-spring-boot-archetype.
…g D)

The previously published 1.0.0 POM carries a phantom
nova-spring-boot-bom:1.0.1 dependency baked in during the brief window
when the BOM was temporarily at 1.0.1 (see nova-docs §11.9.25) and was
never republished after the revert. The starter has now been republished
as 1.0.1 with a clean POM regenerated from the current build.gradle.kts
(which pins nova-spring-boot-bom:1.0.0 directly).
…blish workflow

- pom.xml: 0.1.0-SNAPSHOT -> 1.0.0 to align with nova-bom:1.0.0 API baseline
- publish.yml: manual trigger via workflow_dispatch; reuses
  ahincho/nova-devops/.github/workflows/reusable-publish-maven.yml@main
  (same pattern as nova-bom). Needed to unlock instances/ms-course and
  instances/ms-forum migration (see docs/java/11 plan #1).
@ahincho
ahincho merged commit 0ec89ae into main Jul 21, 2026
4 of 5 checks passed
@ahincho
ahincho deleted the feature/nova-semver-19-20-21-activate-workflows branch July 21, 2026 01:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant