Skip to content

build: pin Java and verify locked Mobile dependency restores - #6

Merged
deku2026 merged 1 commit into
mainfrom
codex/wp02-00-toolchain-locks
Sep 21, 2026
Merged

deku2026 merged 1 commit into
mainfrom
codex/wp02-00-toolchain-locks

Conversation

@deku2026

Copy link
Copy Markdown
Contributor

CI now selects the reviewed Temurin 21 patch from .java-version and explicitly verifies online then offline locked dependency resolution. The existing JVM 21 target and application identity/signing continuity are preserved.

Required release lint detected Contracts ci.60.1. Its independently checksum-verified public Maven artifacts replace ci.54.1 in the exact catalog and generated lock/checksum inputs. All compiled classes and schemas are identical; only notices and source/SBOM identities change. Superseding legal/resource records preserve prior immutable admissions and derive new archive expectations from verified input bytes and the prior public bundle, before candidate construction. No lint check was disabled.

Validation: repository/provenance checks, 49 tooling tests, online/offline Gradle resolution, formatting, shared desktop/Android host and app unit tests, release lint, four real APK/AAB outputs, JVM bytecode verification and full candidate resource/legal/hash verification passed. Local Java uses existing compatible 21.0.11; hosted CI must prove exact 21.0.12 and both device APIs before merge. The local test candidate was not published or persistently signed.

@deku2026
deku2026 merged commit f067f34 into main Sep 21, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant