ci: sign with the EAS-managed keystore (new alias + separate key password)
Some checks failed
Build & Release APK / check (push) Has been cancelled
Build & Release APK / build (push) Has been cancelled

Requires updated repo secrets KEYSTORE_B64, KEYSTORE_PASSWORD, KEY_PASSWORD.
Until they are set, CI release builds fail instead of shipping an APK signed
with the old key that Obtainium would reject.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YE5FmDZmFnWxH6RXCZLcjj
This commit is contained in:
marcuspaico
2026-09-02 21:29:14 +10:00
parent a7efc4079d
commit 4dd8d743a7
2 changed files with 6 additions and 1 deletions

View File

@@ -83,7 +83,10 @@ jobs:
env: env:
KEYSTORE_FILE: /tmp/release.jks KEYSTORE_FILE: /tmp/release.jks
KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }} KEYSTORE_PASSWORD: ${{ secrets.KEYSTORE_PASSWORD }}
KEY_ALIAS: gtd # EAS-managed keystore (since v1.16) — alias is EAS-generated, and the
# key password can differ from the store password.
KEY_ALIAS: a5ff13aa8571055bcaecbaca29a548ae
KEY_PASSWORD: ${{ secrets.KEY_PASSWORD }}
VERSION_CODE: ${{ github.run_number }} VERSION_CODE: ${{ github.run_number }}
VERSION_NAME: 1.${{ github.run_number }} VERSION_NAME: 1.${{ github.run_number }}
run: | run: |

2
.gitignore vendored
View File

@@ -5,3 +5,5 @@ server/.env
server/.env.token.local server/.env.token.local
*.log *.log
.DS_Store .DS_Store
credentials.json
*.jks