Publishing and Artifacts
Publishing from Gradle: publication models, what a software component actually contains, target repositories and credentials, signing, and artifact transforms. Interviewers ask because publishing is where Gradle's variant model becomes visible to the outside world.
on this pageshowhide
explore
- Publication Models25 questions
- maven-publish Plugin5 questions
- POM Customization5 questions
- GAV Coordinates and Versioning5 questions
- ivy-publish Plugin5 questions
- Generated Publish Tasks5 questions
- Components and Variants30 questions
- Software Components5 questions
- Gradle Module Metadata5 questions
- Sources and Javadoc Jars5 questions
- Custom Artifacts and Classifiers5 questions
- Archive Tasks (Jar/Zip)5 questions
- Capabilities and Feature Variants5 questions
- Repositories and Credentials25 questions
- Declaring Maven Repositories5 questions
- Repository Credentials5 questions
- mavenLocal and Snapshot vs Release5 questions
- Sonatype and Maven Central5 questions
- Central Staging Automation5 questions
- Signing15 questions
- Signing Plugin Basics5 questions
- GPG vs In-Memory Keys5 questions
- Conditional and Required Signing5 questions
questions
95 · 4 sectionsHow do you set the groupId, artifactId, and version on a MavenPublication, and how does that relate to project.group and project.version?
basics
~10 sInside a MavenPublication you set groupId, artifactId, and version directly. If you omit them, Gradle defaults groupId to project.group, version to project.version, and artifactId to project.name.
What does the publishToMavenLocal task do, and where does it put your artifacts?
basics
~10 spublishToMavenLocal installs every publication into your local Maven repository on disk (by default ~/.m2/repository), so other local builds can resolve it via mavenLocal().
How do you apply the ivy-publish plugin and declare a basic Ivy publication in a Gradle build?
basics
~10 sApply the ivy-publish plugin, then inside publishing { publications { } } create a publication of type IvyPublication and add a component such as from components.java.
How do you apply the maven-publish plugin and declare a basic Maven publication that publishes your project's Java library?
basics
~10 sApply the maven-publish plugin, then in a publishing { publications { } } block create a publication of type MavenPublication and call from(components["java"]) so it picks up your library's jar and dependencies.
What is the pom { } block on a MavenPublication, and why might you need to populate it before publishing a library?
basics
~10 sThe pom { } block lets you set metadata (name, description, url, licenses, developers, scm) written into the generated pom.xml. You populate it because repositories like Maven Central reject artifacts missing this metadata.
How do the archiveBaseName, archiveVersion, and archiveClassifier properties on an archive task (like Jar) combine to form the final published artifact file name?
basics
~10 sGradle assembles the name as [baseName]-[appendix]-[version]-[classifier].[extension]. So baseName 'app', version '1.0', classifier 'sources' produces app-1.0-sources.jar. Empty parts are skipped along with their dash.
Where in the build script do you attach a custom artifact, and what's the minimal correct snippet to add a fat JAR to a Maven publication?
basics
~10 sInside publishing { publications { ... } }, on the publication, call artifact(tasks.named("fatJar")). That single line adds the fat JAR as an extra file on that publication's coordinates.
How do you make a Gradle Java library publish a sources jar and a javadoc jar alongside the main artifact?
basics
~10 sInside the java { } block call withSourcesJar() and withJavadocJar(). Gradle registers sourcesJar and javadocJar tasks and attaches them to the java component, so they publish automatically.
What is the Gradle Module Metadata (the `.module` file), and what does it describe that a traditional Maven POM cannot?
basics
~20 sIt's a JSON file (module.module) Gradle publishes alongside the POM. It describes a module's variants, their dependencies, and attributes — richer info than a flat POM can express, so Gradle can pick the right variant when resolving.
What is a SoftwareComponent in Gradle, and how does it relate to what gets published?
basics
~10 sA SoftwareComponent describes what a project produces for publication (its artifacts and dependencies). The MavenPublication's from(components.java) reads a component to populate the artifacts and POM/metadata that get published.
What artifacts must a Maven Central release bundle contain beyond the main JAR, and why does Central reject a publication that is missing them?
basics
~10 sEach release must include the main JAR plus a sources JAR, a javadoc JAR, a POM, and PGP/GPG signatures (.asc) for every file. Central validation rejects bundles missing any of these.
How do you supply a username and password to a Maven repository in a Gradle publishing block, and where does Gradle get those values from?
basics
~10 sInside the repository, call credentials(PasswordCredentials::class). Gradle then reads <repoName>Username and <repoName>Password from gradle.properties or environment variables, where <repoName> is the repository's name.
What does the publishToMavenLocal task do, and where does it put your artifacts?
basics
~10 spublishToMavenLocal installs your built artifacts (jar, POM, metadata) into the local Maven cache at ~/.m2/repository, so other local builds on the same machine can resolve them via mavenLocal().
How do you declare a target Maven repository to publish your artifacts to in the maven-publish plugin, and what is the minimum you must specify?
basics
~10 sInside the publishing { repositories { } } block add a maven { } repository and set its url. Optionally give it a name. That tells Gradle where to upload the published artifacts.
What problem does the io.github.gradle-nexus.publish-plugin solve, and what would you have to do manually without it?
basics
~10 sIt automates Sonatype staging: it creates a staging repository, publishes your artifacts into it, then closes and releases it from the build — so you don't click through the Nexus/Central Portal UI by hand.
What does the `isRequired` property in Gradle's signing block control, and why would you set it conditionally instead of leaving it at its default?
basics
~20 sisRequired decides whether a missing or failing signature aborts the build. By default it's true. You set it conditionally (e.g. only for releases) so local or SNAPSHOT builds don't fail when no signing key is configured.
At a basic level, what does the Gradle signing plugin produce, and why does publishing to Maven Central require it?
basics
~10 sIt produces a detached PGP signature (.asc file) for each artifact (jar, POM, sources, javadoc). Maven Central requires these signatures so consumers can verify the artifacts are authentic and untampered.
What does the Gradle `signing` plugin do, and why do you need it when publishing to Maven Central?
basics
~10 sThe signing plugin uses PGP/GPG to create detached .asc signature files for your build artifacts. Maven Central requires every published file to be signed so consumers can verify authenticity.
Walk through how `gradle.taskGraph.hasTask('publish')` works in a conditional signing predicate and why the task graph readiness matters.
basics
~20 sgradle.taskGraph is the resolved DAG of tasks Gradle will run. hasTask('publish') returns true only when a publish task is scheduled. The graph is built after configuration, so the predicate must be read lazily at execution time, not during configuration.
The Gradle signing plugin can obtain a PGP signing key in two main ways: useGpgCmd() and useInMemoryPgpKeys(...). What is the difference between these two approaches and when would you reach for each?
basics
~10 suseGpgCmd() shells out to the local gpg binary and its keyring/agent. useInMemoryPgpKeys() takes the raw ASCII-armored key text and passphrase directly, so no gpg install or keyring is needed — ideal for CI.