Align Android signing hardening with gptme: base64 keystore secret, cert pinning, fail-closed
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 55/100
Research direction
Examine the current Android signing workflow in the Makefile and GitHub Actions. Look at the reference implementation in gptme/gptme's .github/workflows/tauri.yml and docs/contributing.rst. The changes involve modifying the CI/CD pipeline to use a base64-encoded keystore secret, adding certificate pinning verification with apksigner and jarsigner, and ensuring the build fails appropriately. Start by locating the existing signing steps and secrets management.
Written by the indexing model from the issue text.
Description
gptme/gptme#3409 adopted this repo's signing flow (zipalign + apksigner for APKs, jarsigner for AABs, passwords via env) and hardened it. To keep the two projects on one consistent, battle-tested strategy (cross-referenced in #207), migrate this repo to match:
- Deliver the keystore as a base64-encoded secret (e.g.
KEY_ANDROID_JKS_B64) instead of the age-encryptedandroid.jks.agecommitted in-repo; drop the age decryption step andadnsio/setup-age-actiondependency. Keeps the keystore fully private instead of public-but-encrypted, and removes the extra age identity secret. - Pin the expected signer certificate SHA-256 as a non-secret repo/environment variable and verify every APK's signer fingerprint (
apksigner verify --print-certs) plusjarsigner -verify -strictfor AABs before upload. - Fail closed: release-tag builds should error out when signing secrets are missing, instead of the current Makefile fallback that ships unsigned artifacts ("No key secrets set, not signing"). Non-tag CI builds can keep the unsigned path.
- Consider moving the signing secrets into a GitHub environment for scoping.
Reference implementation: gptme/gptme .github/workflows/tauri.yml (release-android job) and docs/contributing.rst "Android release signing".
Note: the store/key passwords stay the same; only the keystore delivery mechanism changes, so this is a workflow-only migration plus one new secret + one variable.
- Dominant language
- Kotlin
- Stars
- 270
- Forks
- 57
- Avg merge
- 20h 32m
- Merged PRs (30d)
- 38
Getting set up
We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from ActivityWatch/aw-android
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
ActivityWatch/aw-android#306 · 1 comment · 1 reaction ·
Maintainers usually reply within 1 day
-
AuthSettingsActivity crashes on launch (InflateException: Material attributes under AppCompat theme)Open
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
ActivityWatch/aw-android#210 · 7 comments · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
ActivityWatch/aw-android#302 ·
Maintainers usually reply within 1 day
-
Difficulty 3/5 1-2 days Newbie friendliness 58/100
ActivityWatch/aw-android#300 · 6 comments ·
Maintainers usually reply within 1 day
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
ActivityWatch/aw-android#296 ·
Maintainers usually reply within 1 day
All issues in ActivityWatch/aw-android
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
Difficulty 1/5 Under an hour Newbie friendliness 95/100
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
recloudstream/cloudstream#3226 · 1 comment ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
aws/aws-crt-kotlin#309 ·
Maintainers usually reply within 3 days
-
OAI-PMH
Difficulty 2/5 1-3 hours Newbie friendliness 78/100