feat: support Maven server credential origins (#1282)
feat: support Maven server credential origins
Refactor origin construction to include port if necessary
Co-authored-by: Copilot Autofix powered by AI 175728472+Copilot@users.noreply.github.com
fix: validate Maven server credential origins
docs: note mvn-server-repository-origins requires Maven 3.10+
Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com
Co-authored-by: Bruno Borges bruno.borges@gmail.com Co-authored-by: Copilot Autofix powered by AI 175728472+Copilot@users.noreply.github.com Co-authored-by: Bruno Borges brborges@microsoft.com Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com
版权所有:中国计算机学会技术支持:开源发展技术委员会
京ICP备13000930号-9
京公网安备 11010802047560号
Setup Java
Set up Java for GitHub Actions workflows.
setup-javainstalls a requested Java distribution, adds it toPATH, configuresJAVA_HOME, and can optionally cache build dependencies for Apache Maven, Gradle, and sbt; generate Maven publishing configuration, verify JDK package signatures, manage multiple JDKs, and manage Maven toolchains.Contents
What it does
lateststable release alias.settings.xml, Maven Toolchains, Maven GPG signing inputs, and environment-variable based credentials for publishing workflows.setup-javaworks with Java, Scala, Kotlin, Gradle, Maven, and sbt projects.What’s new
V6
@actions/*packages.oracle-openjdk), Red Hat Build of OpenJDK (redhat), and Liberica Native Image Kit (liberica-nik), and expanded Tencent Kona support through JDK 25.java-version: latestto resolve the newest stable GA release from the distribution’s remote metadata.18.0.1.1, Temurinjdk+jmodspackages, and native musl artifacts on Alpine for Dragonwell, Corretto, Zulu, and Liberica.force-download: trueto bypass the tool cache and perform a reproducible fresh install.cache-pathand restore-only operation withcache-read-only: true..mvn/extensions.xmlandgradle.properties, preventing stale restores when Maven extensions or Gradle dependency properties change.cacheis set; usecache-jdkto enable or disable it independently.problem-matcher: falseto disable Java compiler and uncaught-exception annotations.GRAALVM_HOMEin addition toJAVA_HOME.server-username->server-username-env-varserver-password->server-password-env-vargpg-passphrase->gpg-passphrase-env-vargpg.passphraseEnvNameinstead of a deprecatedgpg.passphraseserver entry insettings.xml. This requiresmaven-gpg-plugin3.2.0 or newer. See GPG.temurininstead ofadoptoradopt-hotspot, andsemeruinstead ofadopt-openj9.V5
v2.327.1or later. See the runner release notes.java-version-filesupport with.sdkmanrcfiles and automatic distribution detection from SDKMAN and asdf vendor identifiers.set-default: falsefor installing a JDK without changingJAVA_HOMEorPATH.cache-primary-keyoutput.javaccompiler errors.jdkFileinput tojdk-file; the old name remains available as a deprecated alias.Older versions
Usage
Install Eclipse Temurin
Install Microsoft Build of OpenJDK
Read the version from a file
Supported version files are
.java-version,.tool-versions, and.sdkmanrc. A.sdkmanrcfile can also provide the distribution when it contains a recognized suffix, such asjava=21.0.5-tem.Use the newest stable Java
latestresolves the newest stable GA release from remote metadata rather than from the runner tool cache. Distributions that do not publish a release listing (such asoracleandgraalvm) resolve the newest GA feature version from the Adoptium available-releases API and then request that version from their own catalog.latestis not supported withjava-version-file, early-access versions, ordistribution: jdkfile.Inputs
java-versionlatest. Required unlessjava-version-fileis set.java-version-file.java-version,.tool-versions, or.sdkmanrc. Used whenjava-versionis not set.distributionjava-version-filepoints to.sdkmanrcwith a recognized distribution suffix.java-packagejdk,jre,jdk+fx,jre+fx,jdk+crac,jre+crac,jdk+jmods,jdk+jcef,jre+jcef,jdk+ft, orjre+ft. Support varies by distribution.jdkarchitecturex86,x64,armv7,aarch64,ppc64le,ppc64,riscv64, ands390x. Aliasesia32,amd64,arm, andarm64are normalized.jdk-filedistribution: jdkfile.check-latestfalseforce-downloadfalseset-defaultPATHand setJAVA_HOME. Whenfalse, only version-specificJAVA_HOME_<major>_<arch>variables are set.trueproblem-matchertrueverify-signaturetruemakes verification failures fatal.verify-signature-public-keytoken${{ github.token }}on GitHub.com; empty string on GHEScachemaven,gradle, orsbt.cache-jdkcacheis set. Set explicitly totrueorfalseto override.cacheis setcache-dependency-pathcache-pathcache-read-onlyfalseserver-idsettings.xml.githubserver-username-env-varGITHUB_ACTORserver-password-env-varGITHUB_TOKENmvn-server-credentialsserver-id:USERNAME_ENV:PASSWORD_ENV. Replaces the single server configured by the three inputs above when set.mvn-server-repository-originsserver-id:repository-origin. Each origin must belong to a configured server ID. Requires Maven 3.10+.mvn-repositoriesrepository-id:repository-url:snapshots-enabled.mvn-repositories-include-centralfalse, Central is disabled unless an explicitcentralrepository is declared.truemvn-repositories-prioritize-centraltruesettings-pathsettings.xmlis written.~/.m2overwrite-settingssettings.xml.truegpg-private-keygpg-passphrase-env-varGPG_PASSPHRASEwhen a key is setmvn-toolchain-id${mvn-toolchain-vendor}_${java-version}mvn-toolchain-vendor${distribution}show-download-progressfalse, the action adds-ntptoMAVEN_ARGS.falsejava-package: Supported package types arejdk,jre,jdk+fx,jre+fx,jdk+crac,jre+crac,jdk+jmods,jdk+jcef,jre+jcef,jdk+ft, andjre+ft. Availability varies by distribution.Deprecated aliases
jdkFile,server-username,server-password, andgpg-passphraseremain accepted for compatibility, but should be replaced with the current input names.Outputs
distributionversionpathJAVA_HOMEwhenset-defaultis enabled.cache-hitcache-primary-keySupported distributions
correttodragonwellgraalvmgraalvm-communityjetbrainskonalibericaliberica-nikmicrosoftoracleoracle-openjdkredhatsapmachinesemerutemurinzulujdkfileAdditional distribution notes:
arm64toaarch64when querying the Azul Metadata API.distribution: graalvm-communityfor stable JDK 17 and later releases.sudodo not inherit theJAVA_HOMEandPATHset bysetup-javaand may fall back to the system-default JDK.Supported version syntax
java-versionaccepts exact versions, version ranges, early-access versions, andlatest.8,11,17,21,2511.0,11.0.4,17.0,8.0.282+811.0.9.1,18.0.1.1,26.0.2.1+115-ea,15.0.0-ea,27-ealatestWhen
check-latestisfalse, the action first tries the runner tool cache for the requested distribution, package type, architecture, and version range. It downloads Java only when no matching cached version is found. Whencheck-latestistrue, the action checks remote metadata first and downloads if the cached version is not current.GitHub-hosted runners primarily pre-cache Eclipse Temurin JDKs. See the installed Java versions for Ubuntu, Windows, and macOS. On a fresh GitHub-hosted runner, requests for other distributions usually miss the tool cache and resolve from remote metadata. For broad version ranges such as a major version (
21,25), this often behaves similarly tocheck-latest: truebecause the action downloads the latest available release that satisfies the range.Download integrity and signatures
setup-javaautomatically verifies downloaded archive checksums when a selected distribution publishes an authoritative checksum. Automatic checksum verification currently applies totemurin,semeru,corretto,dragonwell,kona,sapmachine,graalvm,graalvm-community,zulu,oracle,oracle-openjdk,microsoft, andjetbrains.Distributions or individual releases without an authoritative checksum continue to install normally, with the omission reported in debug logs. Installations resolved directly from the runner tool cache — including JDKs preinstalled on the runner image and JDKs installed by an earlier step of the same job — are not downloaded again and are not reverified, even when
verify-signature: trueis set. Useforce-download: trueto always download and verify the archive.Package signature verification is supported for
temurinandmicrosoft. Whenverify-signatureis omitted, the action checks the signature and warns if GPG is unavailable or verification fails, but does not enforce the result. Explicitly settingverify-signature: trueenforces verification and makes these failures fatal. Settingverify-signature: truefor an unsupported distribution also fails the workflow.After confirming a legitimate rotation, configure the updated key with
verify-signature-public-key. The input accepts one or more ASCII-armored public keys; concatenate complete armored key blocks when both old and new vendor keys are needed during a transition. Custom keys replace, rather than extend, the keys bundled with the selected distribution.As a temporary fallback while a legitimate rotation is being investigated, set
verify-signature: false. This disables package signature verification, although authoritative checksum verification still applies when the vendor publishes a checksum.Caching
setup-javamanages three kinds of caches. Each one is restored and saved as a separate cache entry.~/.m2/repository,~/.gradle/caches, or the sbt cache pathscachetomaven,gradle, orsbt~/.m2/wrapper/dists,~/.gradle/wrapper)cachetomavenorgradlecacheis set, or explicitly withcache-jdk: true. Opt out withcache-jdk: falseSet
cachetomaven,gradle, orsbtto cache dependencies with minimal configuration.The primary dependency cache key is
setup-java-<runner-os>-<node-arch>-<package-manager>-<file-hash>, where<node-arch>is the runner’s Node.js process architecture. The primary cache stores dependency directories such as~/.m2/repository,~/.gradle/caches, or the sbt cache paths. Its file hash is based on these files by default:**/*.gradle*,**/gradle.properties,**/gradle-wrapper.properties,buildSrc/**/Versions.kt,buildSrc/**/Dependencies.kt,gradle/*.versions.toml,**/versions.properties**/pom.xml,**/.mvn/wrapper/maven-wrapper.properties,**/.mvn/extensions.xml**/*.sbt,**/project/build.properties,**/project/**.scala,**/project/**.sbtUse
cache-dependency-pathto override the files used for key hashing, especially in monorepos:Use
cache-pathwhen the build tool stores dependencies outside the default location:cache-pathchanges what is restored and saved, but not the cache key. Jobs that should share a cache key must use the same OS, architecture, package manager, dependency files, and cache paths.Wrapper caches
Maven and Gradle wrapper distributions are restored and saved as additional cache entries, separate from the primary dependency cache. These entries have their own keys in the form
setup-java-<runner-os>-<node-arch>-<wrapper-cache-name>-<file-hash>.maven-wrapper~/.m2/wrapper/dists**/.mvn/wrapper/maven-wrapper.propertiesgradle-wrapper~/.gradle/wrapper**/gradle-wrapper.propertiesThese wrapper caches are independent from dependency caches, so they remain useful even when dependency files change frequently. The wrapper properties are also part of the Maven and Gradle primary dependency-cache key because wrapper changes can affect how dependencies are resolved, but the wrapper distribution files themselves are stored in the separate wrapper cache entries above.
For advanced Gradle caching features such as build output caching, configuration cache support, encrypted cache storage, cleanup, and fine-grained cache control, consider
gradle/actions/setup-gradle.Caching JDK installations
The JDK cache stores the downloaded JDK installation so later runs skip the download. It is enabled implicitly whenever dependency
cacheis set, so most workflows that cache dependencies are already caching the JDK. Setcache-jdk: trueto enable it without dependency caching, orcache-jdk: falseto opt out while keeping dependency caching. With neithercachenorcache-jdkset, nothing is cached.Read-only caches
Set
cache-read-only: trueto restore dependency, wrapper, and JDK caches without saving changes in the post action. This is useful for pull requests, merge queues, short-lived branches, and matrix fan-out jobs that should only consume caches produced elsewhere.For matrix fan-out, seed the cache once and make matrix jobs read-only consumers:
Cache segment restore timeout
Cache downloads are split into segments. To reduce the chance of a stuck segment blocking a workflow, set
SEGMENT_DOWNLOAD_TIMEOUT_MINS:Multiple JDKs and Maven toolchains
Install multiple Java versions by providing a multiline
java-versionvalue. All configured JDKs are installed. The last one added toPATHbecomes the default.Other installed JDKs are available through version-specific variables such as
JAVA_HOME_17_X64. To use a specific version later in the job, setJAVA_HOMEand prepend itsbindirectory toPATH.setup-javawrites a Maven Toolchains declaration for each installed JDK. When multiple JDKs are installed, the declaration contains all of them. Customize the generated toolchain values withmvn-toolchain-idandmvn-toolchain-vendor.Testing with a Java matrix
Publishing packages
setup-javagenerates Mavensettings.xmland Maven Toolchains configuration. For Gradle publishing, it installs Java for the workflow; the Gradle build file remains responsible for reading credentials from environment variables.Maven
For dependencies hosted outside Maven Central, use
mvn-repositoriesto add resolution repositories to an active profile in the generatedsettings.xml. Repository IDs can matchmvn-server-credentialsIDs when authentication is required. See Resolving Maven dependencies from custom repositories.GPG signing
Maven GPG signing requires
maven-gpg-plugin3.2.0 or newer becausesetup-javapasses the passphrase throughgpg.passphraseEnvName.Recommended permissions
When using the
setup-javaaction in your GitHub Actions workflow, it is recommended to set the following permissions to ensure proper functionality:Publishing workflows may require additional permissions depending on the target registry.
Advanced usage
See advanced usage for detailed examples:
License
The scripts and documentation in this project are released under the MIT License.
Contributions
Contributions are welcome. See our Contributor’s Guide.
Code of Conduct