Volcano

Releases and Compatibility

Consume Volcano safely and maintain binary-compatible library releases.

Versioning

Volcano 2.0 is a deliberate major release. The 1.x builder DSL, tree model, and Volcano() composable were removed in favor of immutable HeatmapNode, rememberHeatmapState, and Heatmap. Keep a 1.x dependency or tag until every consumer can migrate; do not mix the two APIs in a single integration plan.

Kotlin/Compose 2.0.3 preserves valid navigation across immutable data refreshes, supports original-item lookup for aggregated cells, and improves accessible value details. Use 2.0.3 consistently across volcano, volcano-compose, and volcano-compose-coil; see the Kotlin changelog for the release history.

Use the same Volcano version for volcano, volcano-compose, and volcano-compose-coil.

The React npm package is a separate release line. @taewooyo/heatmap-react@0.3.0 adds responsive sizing, refresh-safe state, keyboard navigation, and accessible value details; it uses the npm latest tag. Its version does not match the Kotlin artifact version. React consumers install and upgrade it through npm, and should review the React changelog and TypeScript API reference.

API compatibility

Public Desktop JVM ABI baselines are checked with Binary Compatibility Validator. Maintainers run:

./gradlew :volcano:apiCheck :volcano-compose:apiCheck :volcano-compose-coil:apiCheck

This is an important compatibility signal, but it does not replace behavioral tests across Android, iOS, and Desktop. Consumers should pin a tested version and review release notes before upgrading a major version.

The JVM ABI check does not validate the React package. For React releases, run the package's TypeScript check, build, smoke test, and the browser demo separately.

Publishing a release

The Publish GitHub Actions workflow runs the release verification gate before uploading the volcano, volcano-compose, and volcano-compose-coil artifacts to the Sonatype Central Portal. It runs when a GitHub Release is marked released, or when a maintainer starts the workflow manually.

Configure these repository Actions secrets before publishing:

SecretPurpose
CENTRAL_USERNAME / CENTRAL_PASSWORDCentral Portal user-token credentials
SIGNING_KEY_IDLast eight characters of the GPG key ID
SIGNING_PASSWORDGPG private-key passphrase
SIGNING_KEYASCII-armored GPG private key

The io.github.taewooyo namespace must be verified in Central Portal. Never commit these values to gradle.properties or a workflow file. For a local, unsigned publication-structure check only:

Snapshot publishing uses the same token credentials. Existing OSSRH_USERNAME and OSSRH_PASSWORD secrets are supported as a fallback, but a regular legacy OSSRH password is not a valid Central Portal token and results in 401 Unauthorized.

./gradlew publishToMavenLocal \
  -PRELEASE_SIGNING_ENABLED=false \
  --no-daemon --console=plain

Production publishing remains signing-protected (RELEASE_SIGNING_ENABLED=true).

The Maven Publish workflow does not publish the npm package. npm publication is a separate maintainer action with npm account authentication and package-specific verification.

Consumer verification checklist

  • Build commonMain with the selected Kotlin and Compose Multiplatform toolchain.
  • Render representative localized labels at target font scale.
  • Verify Android Back, iOS safe area, and Desktop resizing.
  • Verify aggregate overview and a drill-down path using production-sized data.
  • Verify image failure behavior if using the optional Coil integration.
  • For React, verify TypeScript integration, SVG sizing, selection/drill-down behavior, and real-browser performance with representative data.

On this page