build: pin Java and verify locked Mobile dependency restores - #6
Merged
Merged
Conversation
Signed-off-by: sammiller <dekueon@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CI now selects the reviewed Temurin 21 patch from .java-version and explicitly verifies online then offline locked dependency resolution. The existing JVM 21 target and application identity/signing continuity are preserved.
Required release lint detected Contracts ci.60.1. Its independently checksum-verified public Maven artifacts replace ci.54.1 in the exact catalog and generated lock/checksum inputs. All compiled classes and schemas are identical; only notices and source/SBOM identities change. Superseding legal/resource records preserve prior immutable admissions and derive new archive expectations from verified input bytes and the prior public bundle, before candidate construction. No lint check was disabled.
Validation: repository/provenance checks, 49 tooling tests, online/offline Gradle resolution, formatting, shared desktop/Android host and app unit tests, release lint, four real APK/AAB outputs, JVM bytecode verification and full candidate resource/legal/hash verification passed. Local Java uses existing compatible 21.0.11; hosted CI must prove exact 21.0.12 and both device APIs before merge. The local test candidate was not published or persistently signed.