From 8c6390571d28ff21a98ed3802458aceddbb6d2a0 Mon Sep 17 00:00:00 2001 From: Lena Date: Sun, 16 Aug 2026 00:00:00 +0000 Subject: build: pin and verify release inputs Support Alpine/musl and Debian/glibc hosts, lock downloaded and Gradle artifacts, and verify native and APK security properties. --- ci/build.sh | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) (limited to 'ci/build.sh') diff --git a/ci/build.sh b/ci/build.sh index c99ec5f..24cd8fc 100755 --- a/ci/build.sh +++ b/ci/build.sh @@ -3,10 +3,15 @@ # Requires the pinned toolchain (see versions): Android SDK + NDK, a JDK, Go. set -eu -root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd) +root=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd) make -C "$root" app -git -C "$root" rev-parse HEAD > "$root/app/build/outputs/apk/release/.source-commit" -echo "ci: APK at app/build/outputs/apk/release/" -ls -l "$root"/app/build/outputs/apk/release/*.apk +if [ -f "$root/keystore.properties" ]; then + apk="$root/app/build/outputs/apk/release/app-release.apk" +else + apk="$root/app/build/outputs/apk/release/app-release-unsigned.apk" +fi +echo "ci: APK at $apk" +ls -l "$apk" +"$root/ci/verify-apk.sh" "$apk" -- cgit v1.2.3