Fix Android APK signing (keystore format) in CI build job
What changed, and why it matters
This commit fixes a small but real bug in the automated build pipeline for Android. Previously, the build script used `echo` to write the signing keystore from a base64-encoded secret. If the secret was empty or missing, `echo` would still create an empty file and the build would continue, potentially producing an unsigned or broken APK. The fix uses `printf '%s'` to avoid adding a trailing newline, and adds a check that aborts the build if the keystore secret is empty. This is a reliability and correctness improvement rather than a direct security vulnerability in the app itself.
No urgent security action required. Reviewers should verify that `ANDROID_KEYSTORE_BASE64` is correctly configured in repository secrets and that the resulting `keystore-orig.jks` is valid. Consider adding a `keytool -list` sanity check after conversion to further harden the pipeline.
Security signals we found
CI secret handling corrected
Silent empty-secret failure prevented
Binary artifact integrity improved
No direct code vulnerability in application logic
Evidence from the diff
In .github/workflows/build.yaml, the CI step that decodes secrets.ANDROID_KEYSTORE_BASE64 into android/keystore-orig.jks was changed from echo "$KEYSTORE_BASE64" | base64 --decode to printf '%s' "$KEYSTORE_BASE64" | base64 --decode. echo appends a newline, which can corrupt a base64 stream or the resulting binary keystore depending on shell behavior. Additionally, a guard [ -s android/keystore-orig.jks ] was added to fail the job if the decoded keystore is zero bytes, preventing silent build failures when the secret is unset. The subsequent keytool -importkeystore conversion step remains unchanged.
Changed components
.github/workflows/build.yamlAndroid release build CI jobAPK signing keystore decoding stepInspect captured patch +2 / −1
diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml
index 929782b..e9dd3ed 100644
--- a/.github/workflows/build.yaml
+++ b/.github/workflows/build.yaml
@@ -169,7 +169,8 @@ jobs:
env:
KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
run: |
- echo "$KEYSTORE_BASE64" | base64 --decode > android/keystore-orig.jks
+ printf '%s' "$KEYSTORE_BASE64" | base64 --decode > android/keystore-orig.jks
+ [ -s android/keystore-orig.jks ] || { echo "ERROR: ANDROID_KEYSTORE_BASE64 secret is empty or not set"; exit 1; }
keytool -importkeystore \
-srckeystore android/keystore-orig.jks \
-destkeystore android/keystore.jks \
Why this scored 18/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.