Copilot commented on code in PR #13770:
URL: https://github.com/apache/cloudstack/pull/13770#discussion_r3701588279


##########
.github/workflows/gradle-publish.yml:
##########
@@ -0,0 +1,44 @@
+# This workflow uses actions that are not certified by GitHub.
+# They are provided by a third-party and are governed by
+# separate terms of service, privacy policy, and support
+# documentation.
+# This workflow will build a package using Gradle and then publish it to 
GitHub packages when a release is created
+# For more information see: 
https://github.com/actions/setup-java/blob/main/docs/advanced-usage.md#Publishing-using-gradle
+
+name: Gradle Package
+
+on:
+  release:
+    types: [created]
+
+jobs:
+  build:
+
+    runs-on: ubuntu-latest
+    permissions:
+      contents: read
+      packages: write
+
+    steps:
+    - uses: actions/checkout@v4
+    - name: Set up JDK 17
+      uses: actions/setup-java@v4
+      with:
+        java-version: '17'
+        distribution: 'temurin'
+        server-id: github # Value of the distributionManagement/repository/id 
field of the pom.xml
+        settings-path: ${{ github.workspace }} # location for the settings.xml 
file
+
+    - name: Setup Gradle
+      uses: 
gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
+
+    - name: Build with Gradle
+      run: ./gradlew build
+
+    # The USERNAME and TOKEN need to correspond to the credentials environment 
variables used in
+    # the publishing section of your build.gradle
+    - name: Publish to GitHub Packages
+      run: ./gradlew publish
+      env:
+        USERNAME: ${{ github.actor }}
+        TOKEN: ${{ secrets.GITHUB_TOKEN }}

Review Comment:
   The `steps:` list is not indented under the `steps` key, which makes this 
workflow invalid YAML and will prevent GitHub Actions from parsing/running it.



##########
.github/workflows/gradle-publish.yml:
##########
@@ -0,0 +1,44 @@
+# This workflow uses actions that are not certified by GitHub.
+# They are provided by a third-party and are governed by
+# separate terms of service, privacy policy, and support
+# documentation.
+# This workflow will build a package using Gradle and then publish it to 
GitHub packages when a release is created
+# For more information see: 
https://github.com/actions/setup-java/blob/main/docs/advanced-usage.md#Publishing-using-gradle
+
+name: Gradle Package
+
+on:
+  release:
+    types: [created]
+
+jobs:
+  build:
+
+    runs-on: ubuntu-latest
+    permissions:
+      contents: read
+      packages: write
+
+    steps:
+    - uses: actions/checkout@v4
+    - name: Set up JDK 17
+      uses: actions/setup-java@v4
+      with:
+        java-version: '17'
+        distribution: 'temurin'
+        server-id: github # Value of the distributionManagement/repository/id 
field of the pom.xml
+        settings-path: ${{ github.workspace }} # location for the settings.xml 
file
+
+    - name: Setup Gradle
+      uses: 
gradle/actions/setup-gradle@af1da67850ed9a4cedd57bfd976089dd991e2582 # v4.0.0
+
+    - name: Build with Gradle
+      run: ./gradlew build
+
+    # The USERNAME and TOKEN need to correspond to the credentials environment 
variables used in
+    # the publishing section of your build.gradle
+    - name: Publish to GitHub Packages
+      run: ./gradlew publish

Review Comment:
   This workflow runs `./gradlew build` / `./gradlew publish`, but this 
repository doesn't include a Gradle wrapper (`gradlew`) or Gradle build files 
(`build.gradle*`). As-is, the workflow will fail immediately on the runner.



##########
.github/workflows/gradle-publish.yml:
##########
@@ -0,0 +1,44 @@
+# This workflow uses actions that are not certified by GitHub.
+# They are provided by a third-party and are governed by
+# separate terms of service, privacy policy, and support
+# documentation.
+# This workflow will build a package using Gradle and then publish it to 
GitHub packages when a release is created
+# For more information see: 
https://github.com/actions/setup-java/blob/main/docs/advanced-usage.md#Publishing-using-gradle
+
+name: Gradle Package
+
+on:
+  release:
+    types: [created]
+
+jobs:
+  build:
+
+    runs-on: ubuntu-latest
+    permissions:
+      contents: read
+      packages: write
+
+    steps:
+    - uses: actions/checkout@v4
+    - name: Set up JDK 17
+      uses: actions/setup-java@v4
+      with:

Review Comment:
   This workflow uses `actions/setup-java@v4` by mutable tag. Other workflows 
in this repo pin third-party actions to a commit SHA (e.g. 
`.github/workflows/build.yml:35`), which reduces supply-chain risk. Consider 
pinning `actions/setup-java` to a specific SHA as well.



##########
.github/workflows/gradle-publish.yml:
##########
@@ -0,0 +1,44 @@
+# This workflow uses actions that are not certified by GitHub.
+# They are provided by a third-party and are governed by
+# separate terms of service, privacy policy, and support
+# documentation.
+# This workflow will build a package using Gradle and then publish it to 
GitHub packages when a release is created
+# For more information see: 
https://github.com/actions/setup-java/blob/main/docs/advanced-usage.md#Publishing-using-gradle
+
+name: Gradle Package
+
+on:
+  release:
+    types: [created]

Review Comment:
   The PR title/description indicates a README update, but the actual change 
adds a new GitHub Actions Gradle publishing workflow. Please update the PR 
title/description to match the change (or adjust the change set if this was 
unintentional).



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to