ITADN

Flaky CI Failure: release-android publish — Sonatype staging API returns 401 Unauthorized

#4025Opengithub-actions[bot] 创建于 9 天前
flaky
## Flaky CI Failure: release-android publish — Sonatype staging API returns 401 Unauthorized **Workflow:** Release **Failed run:** https://github.com/xmtp/libxmtp/actions/runs/32418435638 **Commit:** c30ac5fcd23eddf90efd372578685f325086d2c6 **Failed jobs:** release-android / publish ### Summary The Android release publish job failed at the `:initializeSonatypeStagingRepository` Gradle task. The Sonatype OSSRH staging API at `ossrh-staging-api.central.sonatype.com` responded with HTTP 401 Unauthorized when the job attempted to create a staging repository. This is distinct from the PGP signature failure in #3925 (which was an HTTP 400 during the _close_ step). The 401 here indicates that the Sonatype authentication credentials used by the CI job are invalid, expired, or not being passed correctly. ### Error Details ``` > Task :initializeSonatypeStagingRepository FAILED FAILURE: Build failed with an exception. * What went wrong: Execution failed for task ':initializeSonatypeStagingRepository'. > Failed to create staging repository, server at https://ossrh-staging-api.central.sonatype.com/service/local/ responded with status code 401, body: BUILD FAILED in 1m 1s ##[error]Process completed with exit code 1. ``` ### Analysis A 401 Unauthorized on the _create staging repository_ request means Sonatype rejected the credentials before any artifact or signing validation took place. Likely causes: - **Expired or rotated Sonatype credentials**: The `SONATYPE_USERNAME` and/or `SONATYPE_PASSWORD` (or equivalent token) GitHub Actions secrets may have expired or been rotated without updating the repository secrets. - **Sonatype account/namespace change**: If the Sonatype account transitioned to the new Central Portal (which replaced OSSRH for new accounts), the legacy staging API endpoint at `ossrh-staging-api.central.sonatype.com/service/local/` may require updated credentials or a migration to the new publishing API. - **API token vs. password mismatch**: Sonatype Central may now require an API token rather than a plain username/password pair. This is a **configuration/credentials failure** in the release pipeline, not a transient external outage. It will block every release until the credentials are fixed. --- *Reported by [Flaky Failure Watcher](https://github.com/xmtp/libxmtp/blob/main/.github/workflows/flaky-failure-watcher.yml)*
2 条评论