Do not include dependency metadata in apk
What changed, and why it matters
This change stops the Android app package from embedding a list of its third-party libraries. The commit message says this is needed so F-Droid (an alternative app store focused on privacy and open-source apps) will accept the app, because F-Droid rejects the extra data block that contains that library list. This is a packaging/policy change, not a fix for a code vulnerability. It slightly reduces information an attacker could gather from the published APK, but it does not by itself make the app safer to use.
No security response is required. Treat this as a routine build/packaging change. If reviewing the app for F-Droid publication, verify that the resulting APK no longer contains the Dependency Info Block and that reproducible builds now pass.
Security signals we found
Build metadata disclosure reduction (dependency graph no longer shipped in APK)
F-Droid reproducible-builds compliance change
Evidence from the diff
The patch adds a dependenciesInfo block to android/app/build.gradle.kts, setting includeInApk=false and includeInBundle=true. In modern Android Gradle Plugin builds, this controls whether the Dependency Info Block (a signing block containing a Protobuf-encoded dependency graph) is written into the APK. F-Droid’s reproducible-builds checks reject APKs containing this block because it can vary between builds and contains non-reproducible metadata. The change is therefore a build-configuration adjustment to satisfy F-Droid publishing requirements. It is not a runtime security bug fix and does not alter app code, permissions, or attack surface in a meaningful way.
Changed components
android/app/build.gradle.kts build configurationInspect captured patch +5 / −0
diff --git a/android/app/build.gradle.kts b/android/app/build.gradle.kts
index 8328ff0..6caae74 100644
--- a/android/app/build.gradle.kts
+++ b/android/app/build.gradle.kts
@@ -20,6 +20,11 @@ android {
compileSdk = flutter.compileSdkVersion
ndkVersion = "28.1.13356709"
+ dependenciesInfo {
+ includeInApk = false // fdroid rejects extra signing blocks
+ includeInBundle = true
+ }
+
compileOptions {
isCoreLibraryDesugaringEnabled = true
sourceCompatibility = JavaVersion.VERSION_11
Why this scored 19/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.