Fix Android APK signing (keystore format) in CI build job
What changed, and why it matters
This commit changes the GitHub Actions build workflow for the Stack Wallet Android app. It adds a step that converts the uploaded Android signing keystore from its original format into the PKCS12 format before building the APK. This is a CI/build pipeline fix and does not, on its own, introduce a vulnerability. It does mean the CI job now handles the app's private signing keystore and its password, so the security of the build pipeline remains important.
No immediate security action is required from the diff alone. As routine hygiene, verify that secrets.ANDROID_KEYSTORE_BASE64 and secrets.ANDROID_STORE_PASSWORD are scoped only to this workflow/job, rotated periodically, and that build logs do not echo the password or keystore contents. Confirm the legacy PKCS12 flag is required and not masking a broader key format issue.
Security signals we found
CI workflow handles base64-encoded Android signing keystore secret
CI workflow handles Android keystore password secret
keytool conversion uses legacy PKCS12 provider flag
Original keystore file is removed after conversion in the same job
No evidence of secret leakage, hardcoding, or unauthorized access in the diff
Evidence from the diff
The patch updates .github/workflows/build.yaml. Previously the workflow base64-decoded secrets.ANDROID_KEYSTORE_BASE64 directly into android/keystore.jks. Now it decodes to android/keystore-orig.jks, runs keytool -importkeystore to convert it to PKCS12 (-deststoretype pkcs12) with -J-Dkeystore.pkcs12.legacy, writes the result to android/keystore.jks, deletes the original, and then creates android/key.properties referencing the converted keystore. The change is framed as fixing APK signing by ensuring the keystore is in the format expected by the newer build tooling.
Changed components
.github/workflows/build.yamlAndroid CI build jobAndroid APK signing stepInspect captured patch +10 / −1
diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml
index 5bb1216..929782b 100644
--- a/.github/workflows/build.yaml
+++ b/.github/workflows/build.yaml
@@ -169,7 +169,16 @@ jobs:
env:
KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
run: |
- echo "$KEYSTORE_BASE64" | base64 --decode > android/keystore.jks
+ echo "$KEYSTORE_BASE64" | base64 --decode > android/keystore-orig.jks
+ keytool -importkeystore \
+ -srckeystore android/keystore-orig.jks \
+ -destkeystore android/keystore.jks \
+ -deststoretype pkcs12 \
+ -srcstorepass "${{ secrets.ANDROID_STORE_PASSWORD }}" \
+ -deststorepass "${{ secrets.ANDROID_STORE_PASSWORD }}" \
+ -noprompt \
+ -J-Dkeystore.pkcs12.legacy
+ rm android/keystore-orig.jks
cat > android/key.properties <<EOF
storeFile=../keystore.jks
storePassword=${{ secrets.ANDROID_STORE_PASSWORD }}
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.