// the find
chrisbanes/gradle-mvn-push
Helper to upload Gradle Android Artifacts to Maven repositories
A single Gradle script (plus a blog post) for publishing Android AAR artifacts to Maven Central via Sonatype's staging/snapshot servers. Aimed at Android library maintainers in the pre-Gradle-Nexus-Publish-Plugin era who need signing and POM generation wired up without writing it themselves.
Handles the fiddly parts correctly: separates snapshot vs release upload targets based on whether VERSION_NAME contains 'SNAPSHOT', supports GPG signing via keyId/password/secretKeyRingFile, and generates a proper POM with SCM and license metadata that Maven Central actually requires. It's a known-working reference — plenty of real Android libraries from the 2013-2015 era copied this exact file.
Last commit is 2020, and it predates the Gradle plugin ecosystem's move away from the classic apply-from-URL pattern — applying a script directly from a raw GitHub URL at build time is a supply-chain risk that no modern build should accept. It only supports the legacy Sonatype OSSRH upload flow (uploadArchives/Maven plugin), not the maven-publish plugin or the newer Central Publisher Portal, and secretKeyRingFile-based signing is deprecated in favor of in-memory keys. This is a historical artifact, not something to add to a project today — use the Gradle Nexus Publish Plugin or vanniktech's maven-publish plugin instead.