Skip to content

Add force-download option for reproducible builds #979

Description

@craigraw

Description:
Add a new option to this task to force a download of the JDK, rather than use the installed version in the tool cache. For example:

  - uses: actions/setup-java@v5
    with:
      distribution: temurin
      java-version: '25.0.2'
      force-download: true  # New option - ignore tool-cache

Justification:
Currently, GitHub runner images use apt-get install temurin-${version}-jdk to pre-install Java. Adoptium's Debian packages include a dependency on adoptium-ca-certificates (or integrate with
ca-certificates-java). The cacerts file gets symlinked to /etc/ssl/certs/adoptium/cacerts, which is a shared keystore that integrates with the system's certificate store via update-ca-certificates.

This means the version of cacerts in the tool-cache is system dependent. When using a tool like jlink/jpackage, the cacerts gets bundled into the custom Java runtime image, making the build non-reproducible.

Forcing this action to perform a fresh download means that Java is simply extracted from the relevant .zip or tar.gz without modification of the cacerts file, resolving the issue.

Workaround
The workaround for now is to delete any Java installations in the tool-cache before running setup-java:

  - name: Clear Java tool-cache for reproducibility
    shell: bash
    run: rm -rf "$RUNNER_TOOL_CACHE"/Java_*

Activity

  1. v-gowridurgad commented on Feb 9, 2026

    @v-gowridurgad
    Contributor

    Hello @craigraw👋,
    Thank you for reporting this feature request. We will investigate it and get back to you as soon as we have some feedback.

  2. brunoborges commented on Jul 14, 2026

    @brunoborges
    Contributor

    @craigraw how is the workaround helping with the ca-certs?

  3. craigraw commented on Jul 15, 2026

    @craigraw
    Author

    @brunoborges Can you be more specific? The workaround ensures a consistent cacerts file.

  4. brunoborges commented on Jul 15, 2026

    @brunoborges
    Contributor

    The workaround deletes the JDK but not the CA certs?

  5. craigraw commented on Jul 15, 2026

    @craigraw
    Author

    It deletes the cached JDK in the runner, including the cacerts it contains. setup-java then installs a fresh JDK (without any interference from the system certificates).

  6. brunoborges commented on Jul 15, 2026

    @brunoborges
    Contributor

    @craigraw have you tested with check-latest: true ?

  7. craigraw commented on Jul 16, 2026

    @craigraw
    Author

    Yes, I did. With check-latest: true, setup-java queries the remote manifest for the newest version satisfying the spec instead of accepting whatever is in the tool cache - but it then checks whether that resolved version already exists in the cache, and if it does, it uses the cached copy anyway.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

feature requestNew feature or request to improve the current logic

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions