aboutsummaryrefslogtreecommitdiff
path: root/versions
AgeCommit message (Collapse)AuthorFilesLines
7 daysbuild: pin the build host and the shipped ABIsLena1-2/+3
The native scripts picked an NDK host tag for macOS as well, but ci/setup-toolchain.sh provisions nothing outside Linux x86_64 and no pipeline exercises the other branch. Fail with the message setup already gives instead of naming a toolchain nobody can obtain here. The armeabi-v7a and x86 cases were never reachable either: ABIS ships arm64-v8a and x86_64, and ci/verify-apk.sh has no machine check for the other two, so adding one to ABIS failed the build it was meant to enable. Record what a new ABI actually costs instead of inviting a one-line edit that cannot work.
14 daysapp: release 0.2.00.2.0Lena1-2/+2
Document the multi-remote release, publish matching store metadata, and advance the version once from the released 0.1.3 base.
14 daysbuild: pin and verify release inputsLena1-11/+22
Support Alpine/musl and Debian/glibc hosts, lock downloaded and Gradle artifacts, and verify native and APK security properties.
14 daysnative: harden rsync and SSH transportLena1-4/+6
Update rsync to 3.5.0 and Go to 1.26.6. Bound SSH handshakes, pin host-key types, and build 16 KB-aligned hardened executables.
2026-07-13ci: pin toolchains and verify release artifactsLena1-0/+9
Checksum-pin every downloaded toolchain archive. Before publishing, verify the APK was built from HEAD, the tag matches versionName, apksigner passes, and the tree is clean; publish a sha256 sidecar and treat published assets as immutable. Compare full unsigned APKs in verify-repro and run the Android unit tests in CI.
2026-07-01ci: pin the exact JDK releaseLena1-0/+2
The Adoptium "latest 17 GA" endpoint floats while versions promises never to float. Pin the full Temurin build and fetch it by version.
2026-01-01rsend: push phone folders to a home SSH host over rsyncLena1-0/+28
A small Android app for one-way folder backup, a KISS alternative to Syncthing. It bundles rsync (built from pinned source via the NDK) and a pure-Go SSH transport, both shipped in the APK as lib*.so and run from the native library directory. rsend pins the host key, stores the ed25519 identity Keystore-encrypted, pushes each folder additively or as a mirror, and runs on demand or on a WiFi-only schedule. The build is self-contained and reproducible: make setup provisions the toolchain, make builds rsync, rsh, and the APK.