Prerequisite:

You need GPG installed (comes along with GIT installation in the \bin folder) and you need to create a keyring, used for signing artifacts.
If you have an existing key, simply import it:

gpg --allow-secret-key-import --import <keyring>.gpg

That, or you can install one of the binaries to import the key, from here: https://www.gnupg.org/download/index.html

To import the keyring in a CI/CD environment (CircleCI, Azure Devops, Bamboo, Jenkins etc.), you need to import the keyring
externally (or us a private Repo). Alternatively you can import the ASCII export of the key configured as a property secret
so you can ECHO it to a file during the build. Once exposed as file, you can use it to sign:

To generate the ASCII export of a key so you can store it a secret property in your build environment:
    - gpg --no-default-keyring --armor --secret-keyring ./secring.gpg --keyring ./pubring.gpg --export-secret-key USER > secring.gpg.asc
    - sed ':a;N;$!ba;s/\n/\\n/g' secring.gpg.asc, OR
    - base64 encode the text

To be able to have your CI/CD script also commit the new version, you need to add github.com's official host finger print.
    - https://serverfault.com/a/701637/157338
    - https://discuss.circleci.com/t/error-sending-to-agent-inappropriate-ioctl-for-device/17465/2
    - https://medium.com/@Joachim8675309/generating-gpg-key-files-cc447431415a
    - http://frankiesardo.github.io/posts/2015-04-19-automate-everything-with-circleci.html
    - https://github.com/toknapp/arweave4s/blob/master/.circleci/config.yml
    - https://serverfault.com/questions/447028/non-interactive-git-clone-ssh-fingerprint-prompt
    - https://superuser.com/questions/232373/how-to-tell-git-which-private-key-to-use

To release through CI/CD pipeline in CircleCI

 1. run the defensive Dependabot sweep from MAINTAINER_WORKFLOW.md, merge safe patch-level library updates, and rerun full JDK 8 verification
 2. update release notes, RELEASE_HISTORY.md and the github readme page according to MAINTAINER_WORKFLOW.md, then push changes
 3. create or reuse the exact-version GitHub milestone with the planned release date as its due date, assign all release issues/PRs (including accounted-for closed Dependabot work), and cross-check the release-note links
 4. go to the CI/CD pipeline https://circleci.com/gh/bbottema/simple-java-mail
 5. select the version release needed
 6. after a successful release, verify every milestone item is closed, replace the milestone due date with the actual published release date, and close the milestone

To release manually:

 1. run the defensive Dependabot sweep from MAINTAINER_WORKFLOW.md, merge safe patch-level library updates, and rerun full JDK 8 verification
 2. update release notes, RELEASE_HISTORY.md and the github readme page according to MAINTAINER_WORKFLOW.md (don't commit)
 3. create or reuse the exact-version GitHub milestone with the planned release date as its due date, assign all release issues/PRs (including accounted-for closed Dependabot work), and cross-check the release-note links
 4. remove SNAPSHOT version from the <version> property
 5. mvn -DperformRelease=true clean deploy
            (set password in settings.xml or use local pgp key password, for which the public key must have been sent to a public key server,
            eg: gpg --keyserver hkp://keyserver.ubuntu.com --send-keys 05AC6403)
		    server needed in settings.xml (see below)
 6. Go to https://oss.sonatype.org and release the artifact so it is submitted to Maven Central
 7. set the exact-version milestone due date to the actual published release date and close it after every included issue and PR is closed
 8. add new SNAPSHOT version to the <version> property, execute and commit everything

    maven's settings.xml:

        <server>
          <id>ossrh</id>
          <username>sonatype user</username>
          <password>sonatype password</password>
        </server>

    To have a global gpg password so that it will use that automatically:

        <profiles>
            <profile>
                <id>gpg</id>
                <properties>
                    <gpg.executable>gpg</gpg.executable>
                    <gpg.passphrase>password</gpg.passphrase>
                </properties>
            </profile>
        </profiles>
        <activeProfiles>
            <activeProfile>gpg</activeProfile>
        </activeProfiles>
