Skip to content

Fix snapshot deploy 401 on Maven 3.10 - #840

Merged
oryan-block merged 1 commit into
masterfrom
bugfix/snapshot-credential-scope
Oct 7, 2026
Merged

oryan-block merged 1 commit into
masterfrom
bugfix/snapshot-credential-scope

Conversation

@oryan-block

Copy link
Copy Markdown
Collaborator

Snapshot publishing has been failing since the runner image moved to ubuntu24/20261004.327, which ships Maven 3.10.0 (failing run).

Maven 3.10 only sends a server's credentials to that server's <repositoryOrigins>, and for id central the default origin is https://repo.maven.apache.org. setup-java can't declare origins yet, so the deploy to central.sonatype.com was sent without credentials and returned a 401:

[WARNING] Not using credentials of server 'central' for repository https://central.sonatype.com/repository/maven-snapshots/: the origins declared for this id are [https://repo.maven.apache.org].

This passes -Dmaven.repository.credentialScope=id to switch back to the Maven 3.9 behaviour (credentials matched by id only). It's a stopgap: once setup-java releases mvn-server-repository-origins (actions/setup-java#1282), we should declare the origin there instead.

🤖 Generated with Claude Code

Maven 3.10 (runner image ubuntu24/20261004.327) only sends server
credentials to the server's repository origins, and setup-java can't
declare those yet, so the snapshot deploy to central.sonatype.com
was sent without credentials and got a 401.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

@oryan-block
oryan-block merged commit acc0cdf into master Oct 7, 2026
6 checks passed
@oryan-block
oryan-block deleted the bugfix/snapshot-credential-scope branch October 7, 2026 16:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant