Description:
Add a new input mvn-plugin-repositories to the Maven settings generation, analogous to mvn-repositories:
Format: multiline list of repository-id:repository-url:snapshots-enabled.
The entries are written as into the generated setup-java-repositories profile in settings.xml.
mvn-repositories-include-central: false should also disable Maven Central as a plugin repository. Otherwise the Super POM's central plugin repository stays active.
Repository IDs should match mvn-server-credentials IDs for authentication, as with mvn-repositories.
Example:
- uses: actions/setup-java@v6
with:
distribution: temurin
java-version: '21'
mvn-server-credentials: |
private:PRIVATE_REPOSITORY_USERNAME:PRIVATE_REPOSITORY_TOKEN
mvn-repositories: |
private:https://maven.example.com/releases:false
mvn-plugin-repositories: |
private:https://maven.example.com/releases:false
mvn-repositories-include-central: false
Justification:
mvn-repositories only generates , which Maven uses for project dependencies. Maven resolves build plugins through , which the action cannot configure. Even with mvn-repositories-include-central: false and a private repository set up, plugins are still resolved from Maven Central.
This fails for plugins that are only available in a private repository, e.g. commercial plugins mirrored in an internal Artifactory:
The current workaround is a custom step that patches ~/.m2/settings.xml after setup-java has run, or a hand-written settings.xml with overwrite-settings: false. Both defeat the purpose of the mvn-repositories and mvn-server-credentials inputs. In corporate environments where all artifacts, including plugins, must come from an internal repository, this is a common requirement.
Description:
Add a new input mvn-plugin-repositories to the Maven settings generation, analogous to mvn-repositories:
Format: multiline list of repository-id:repository-url:snapshots-enabled.
The entries are written as into the generated setup-java-repositories profile in settings.xml.
mvn-repositories-include-central: false should also disable Maven Central as a plugin repository. Otherwise the Super POM's central plugin repository stays active.
Repository IDs should match mvn-server-credentials IDs for authentication, as with mvn-repositories.
Example:
Justification:
mvn-repositories only generates , which Maven uses for project dependencies. Maven resolves build plugins through , which the action cannot configure. Even with mvn-repositories-include-central: false and a private repository set up, plugins are still resolved from Maven Central.
This fails for plugins that are only available in a private repository, e.g. commercial plugins mirrored in an internal Artifactory:
The current workaround is a custom step that patches ~/.m2/settings.xml after setup-java has run, or a hand-written settings.xml with overwrite-settings: false. Both defeat the purpose of the mvn-repositories and mvn-server-credentials inputs. In corporate environments where all artifacts, including plugins, must come from an internal repository, this is a common requirement.