Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Align Android signing hardening with gptme: base64 keystore secret, cert pinning, fail-closed

Open
#208 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
55/100
Issue type
Refactor
Clarity
Clearly specified
Activity status
Quiet
Tech stack
android, github-actions, kotlin, rust

Research direction

Examine the current Android signing workflow in the Makefile and GitHub Actions. Look at the reference implementation in gptme/gptme's .github/workflows/tauri.yml and docs/contributing.rst. The changes involve modifying the CI/CD pipeline to use a base64-encoded keystore secret, adding certificate pinning verification with apksigner and jarsigner, and ensuring the build fails appropriately. Start by locating the existing signing steps and secrets management.

Written by the indexing model from the issue text.

Description

gptme/gptme#3409 adopted this repo's signing flow (zipalign + apksigner for APKs, jarsigner for AABs, passwords via env) and hardened it. To keep the two projects on one consistent, battle-tested strategy (cross-referenced in #207), migrate this repo to match:

  • Deliver the keystore as a base64-encoded secret (e.g. KEY_ANDROID_JKS_B64) instead of the age-encrypted android.jks.age committed in-repo; drop the age decryption step and adnsio/setup-age-action dependency. Keeps the keystore fully private instead of public-but-encrypted, and removes the extra age identity secret.
  • Pin the expected signer certificate SHA-256 as a non-secret repo/environment variable and verify every APK's signer fingerprint (apksigner verify --print-certs) plus jarsigner -verify -strict for AABs before upload.
  • Fail closed: release-tag builds should error out when signing secrets are missing, instead of the current Makefile fallback that ships unsigned artifacts ("No key secrets set, not signing"). Non-tag CI builds can keep the unsigned path.
  • Consider moving the signing secrets into a GitHub environment for scoping.

Reference implementation: gptme/gptme .github/workflows/tauri.yml (release-android job) and docs/contributing.rst "Android release signing".

Note: the store/key passwords stay the same; only the keystore delivery mechanism changes, so this is a workflow-only migration plus one new secret + one variable.

Dominant language
Kotlin
Stars
270
Forks
57
Avg merge
20h 32m
Merged PRs (30d)
38

Getting set up

We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from ActivityWatch/aw-android

All issues in ActivityWatch/aw-android

Similar issues

More Kotlin issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.