aboutsummaryrefslogtreecommitdiff
path: root/settings.gradle
diff options
context:
space:
mode:
authorLena <lena@omega>2026-07-01 00:00:00 +0000
committerLena <lena@omega>2026-07-01 00:00:00 +0000
commit0f88f2c1e5e108021ccddeee24f1216107115791 (patch)
tree1a045221b85c1d5a83e2fd040c4260834a62300b /settings.gradle
parentff7acf898b48359275a5b09b82ed926a945233f8 (diff)
downloadscrcpy-android-0f88f2c1e5e108021ccddeee24f1216107115791.tar.gz
build: verify release inputs
Pin and verify what goes into a release: JitPack confined to the SPAKE2 module via exclusiveContent, the vendored subtree pulled by commit SHA instead of a mutable tag, a pinned Docker base digest with a checksummed cmdline-tools download, and a verifyScrcpyServer task wired into every assets merge. The expected server checksum can be overridden with -PscrcpyServerSha256 when the jar is built from source. build-apk now requires apksigner and fails unless independent signature verification succeeds. Split the test image into unit and e2e targets so JVM-only test runs do not download an emulator. Ship THIRD_PARTY_NOTICES and the LGPL text for SPAKE2 in the APK. Add scripts/check as the host quality gate.
Diffstat (limited to 'settings.gradle')
-rw-r--r--settings.gradle13
1 files changed, 10 insertions, 3 deletions
diff --git a/settings.gradle b/settings.gradle
index 78b1a9c..060839b 100644
--- a/settings.gradle
+++ b/settings.gradle
@@ -11,9 +11,16 @@ dependencyResolutionManagement {
repositories {
google()
mavenCentral()
- // JitPack is required for spake2-android, pulled in by :adb (libadb-android).
- // Kept at settings level so the :adb module stays untouched upstream.
- maven { url 'https://jitpack.io' }
+ // JitPack is used only for libadb's SPAKE2 pairing bridge. Do not
+ // allow it to shadow artifacts available from the primary repos.
+ exclusiveContent {
+ forRepository {
+ maven { url 'https://jitpack.io' }
+ }
+ filter {
+ includeModule 'com.github.MuntashirAkon.spake2-java', 'spake2-android'
+ }
+ }
}
}