From 4dd8d743a77c45e2aae5ace407cffd987159efac Mon Sep 17 00:00:00 2001 From: marcuspaico Date: Wed, 2 Sep 2026 21:29:14 +1000 Subject: [PATCH] ci: sign with the EAS-managed keystore (new alias + separate key password) Requires updated repo secrets KEYSTORE_B64, KEYSTORE_PASSWORD, KEY_PASSWORD. Until they are set, CI release builds fail instead of shipping an APK signed with the old key that Obtainium would reject. Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_01YE5FmDZmFnWxH6RXCZLcjj --- .gitea/workflows/release.yml | 5 ++++- .gitignore | 2 ++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 760bd66..97bc093 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -83,7 +83,10 @@ jobs: env: KEYSTORE_FILE: /tmp/release.jks KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }} - KEY_ALIAS: gtd + # EAS-managed keystore (since v1.16) — alias is EAS-generated, and the + # key password can differ from the store password. + KEY_ALIAS: a5ff13aa8571055bcaecbaca29a548ae + KEY_PASSWORD: ${{ secrets.KEY_PASSWORD }} VERSION_CODE: ${{ github.run_number }} VERSION_NAME: 1.${{ github.run_number }} run: | diff --git a/.gitignore b/.gitignore index a0e9638..c34e948 100644 --- a/.gitignore +++ b/.gitignore @@ -5,3 +5,5 @@ server/.env server/.env.token.local *.log .DS_Store +credentials.json +*.jks