Skip to content

feat(native-shell-android): SD-04 — add Maven publishing - #1932

Merged
jcortejoso merged 5 commits into
self-2469/sdk-distributionfrom
self-2473/sd-04-android-maven
Apr 8, 2026
Merged

jcortejoso merged 5 commits into
self-2469/sdk-distributionfrom
self-2473/sd-04-android-maven

Conversation

@jcortejoso

@jcortejoso jcortejoso commented Apr 7, 2026 •

Copy link
Copy Markdown
Member

Summary

Implements SD-04 from SELF-2473 — add Maven publishing so integrators can add the native shell as a Gradle dependency.

  • build.gradle.kts — Added maven-publish plugin and publishing block with groupId=xyz.self.sdk, artifactId=native-shell-android, version=0.1.0; added GitHub Packages repository with credentials resolved from GITHUB_ACTOR/GITHUB_TOKEN env vars or gpr.user/gpr.token project properties
  • .github/workflows/publish-android-sdk.yml — New manual-dispatch workflow (workflow_dispatch) with a version string input and a dry-run boolean (default true); dry-run publishes to Maven Local for validation, non-dry-run publishes the release AAR to GitHub Packages

Test plan

  • ./gradlew publishToMavenLocal ✅ BUILD SUCCESSFUL
  • GitHub Actions dry-run publish workflow ✅ completed successfully
  • POM includes correct runtime dependencies (appcompat, webkit, kotlinx-serialization-json, kotlinx-coroutines-android) ✅

Usage

// settings.gradle.kts
dependencyResolutionManagement {
    repositories {
        maven {
            url = uri("https://maven.pkg.github.com/selfxyz/self")
            credentials {
                username = providers.gradleProperty("gpr.user").orNull ?: System.getenv("GITHUB_ACTOR")
                password = providers.gradleProperty("gpr.token").orNull ?: System.getenv("GITHUB_TOKEN")
            }
        }
    }
}

// build.gradle.kts
dependencies {
    implementation("xyz.self.sdk:native-shell-android:0.1.0")
}

Native Consolidation Checklist

  • CONTRACTS.md reviewed - no unintended contract changes
  • Layer 1 bridge contract tests pass (cd app && yarn jest:run / yarn workspace @selfxyz/rn-sdk-test-app test)
  • Layer 3 builds pass (app iOS, RN test app iOS, RN test app Android)
  • Layer 4 manual smoke test signed off (if consolidation PR)
  • No new native business logic added (logic belongs in TypeScript)

Add maven-publish plugin with groupId=xyz.self.sdk,
artifactId=native-shell-android, version=0.1.0.

Verified: publishToMavenLocal succeeds, AAR contains no bundled
web assets, POM includes correct runtime dependencies.

Ref: SELF-2473
@vercel

vercel Bot commented Apr 7, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
self-webview-app Ready Ready Preview, Comment Apr 7, 2026 8:39am

Request Review

@coderabbitai

coderabbitai Bot commented Apr 7, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

🗂️ Base branches to auto review (3)
  • main
  • dev
  • staging

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 35e1aef3-7d20-451e-a845-18079fae3b1a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch self-2473/sd-04-android-maven

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

- Add GitHubPackages maven repository to publishing block
  (credentials from GITHUB_ACTOR/GITHUB_TOKEN env or gpr.user/gpr.token properties)
- Add publish-android-sdk.yml workflow (manual dispatch with version input)
  - Builds, tests, then publishes release AAR to GitHub Packages

Ref: SELF-2473
Defaults to dry-run (publishToMavenLocal) so the workflow can be
tested safely. Uncheck dry-run to publish to GitHub Packages.

Ref: SELF-2473
@jcortejoso

Copy link
Copy Markdown
Member Author

@copilot review
@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. What shall we delve into next?

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copilot AI commented Apr 7, 2026

Copy link
Copy Markdown

@copilot review
@codex review

Code Review — SD-04 Android Maven Publishing

CI is green (Native Shells CI ✅, Publish Android SDK dry-run ✅). Below are the findings.


build.gradle.kts

  1. Redundant groupId — group = "xyz.self.sdk" is already set at the top level (line 20), so setting groupId = "xyz.self.sdk" inside the publication block is redundant. One or the other is sufficient.

  2. No POM metadata — The publication lacks a pom {} block with description, licenses, developers, and scm fields. GitHub Packages will host the artifact without them, but Maven Central (and good hygiene for published libraries) expects these. Recommend adding at minimum description and licenses.

  3. No sources artifact — Integrators using IDE code navigation rely on a sources JAR. Should add artifact(tasks.register("sourcesJar", Jar::class) { ... archiveClassifier.set("sources") }) to the publication or configure publishing.publications["release"].artifact(sourcesJar).


.github/workflows/publish-android-sdk.yml

  1. Inconsistent if: expression syntax — The dry-run condition uses bare if: inputs.dry-run while the negation uses if: ${{ !inputs.dry-run }}. Should use ${{ }} for both to be consistent and unambiguous:

    if: ${{ inputs.dry-run }}
    ...
    if: ${{ !inputs.dry-run }}
  2. Shell injection via sed — The version is injected directly into a sed command:

    sed -i "s/version = \".*\"/version = \"${{ inputs.version }}\"/" build.gradle.kts

    If inputs.version contains /, ", or \, the sed delimiter breaks or the command errors. Low risk given workflow_dispatch is gated to authorized users, but the idiomatic Gradle approach is a -P property:

    - name: Build
      run: ./gradlew build -PsdkVersion=${{ inputs.version }}
    // build.gradle.kts
    version = project.findProperty("sdkVersion") as String? ?: "0.1.0"
  3. No version format validation — There's no constraint on the version input. A typo like v0.1.0 instead of 0.1.0 would publish a malformed version string. Adding a simple regex check (or documenting expected format more strictly) would prevent this.

  4. Missing gradle/actions/setup-gradle — The CI workflow (native-shells-ci.yml:58) uses gradle/actions/setup-gradle@v4 for Gradle daemon management and build scans, but the publish workflow does not. Low impact but inconsistent.


Summary

Blocking: none — the implementation is functionally correct and CI passes.
Recommended before merge: items 4 (inconsistent if: syntax) and 5 (sed injection).
Nice-to-have: items 1, 3, 6, and 7.

@jcortejoso
jcortejoso merged commit 2275069 into self-2469/sdk-distribution Apr 8, 2026
13 checks passed
@jcortejoso
jcortejoso deleted the self-2473/sd-04-android-maven branch April 8, 2026 06:25

This branch was successfully deployed

1 active deployment
Preview – self-webview-app — 6bcb6ee9 Deployed Apr 7, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants