fix: 签名 fallback 限制到 CI 环境,本地构建缺 release.jks 时报错
修复 chatgpt-codex-connector review 指出的问题: 原逻辑在任何机器缺 release.jks 时都静默 fallback 到 debug keystore, 可能生成不安全的 debug 签名 Release APK 而无任何错误提示。 改为仅 CI=true 时才 fallback,本地构建直接 GradleException 报错。
This commit is contained in:
parent
29877c00ce
commit
74a4e3d494
@ -183,7 +183,7 @@ Expanded(平板,≥840dp):
|
||||
1. `test`:`testDebugUnitTest` + `lintDebug`,上传 XML 测试报告 + lint 报告 artifact
|
||||
2. `build-debug`:`assembleDebug`,上传 Debug APK artifact
|
||||
3. `build-release`:`assembleRelease` + APK 完整性验证(`AndroidManifest.xml` + `resources.arsc` + `res/`),上传 Release APK artifact
|
||||
- Release 签名 fallback:CI 无 `release.jks`,`build.gradle.kts` 自动 fallback 到 `~/.android/debug.keystore`;CI 额外步骤确保 debug keystore 存在
|
||||
- Release 签名 fallback:CI 无 `release.jks`,`build.gradle.kts` 仅在 `CI=true` 环境变量下 fallback 到 `~/.android/debug.keystore`;本地构建缺 `release.jks` 时直接 `GradleException` 报错,防止静默生成 debug 签名的 Release APK
|
||||
- artifact 保留 14 天
|
||||
|
||||
**重大修改 PR 审计红线**:
|
||||
|
||||
@ -36,12 +36,21 @@ android {
|
||||
keyAlias = System.getenv("KEYSTORE_ALIAS") ?: "rainy"
|
||||
keyPassword = System.getenv("KEY_PASSWORD") ?: "RainyToken2026!"
|
||||
} else {
|
||||
// Fallback: 使用 SDK 默认 debug keystore(CI 构建验证用)
|
||||
// 仅在 CI 环境中 fallback 到 debug keystore(用于编译/资源完整性验证)
|
||||
// 本地构建缺少 release.jks 时直接报错,避免静默生成 debug 签名的 Release APK
|
||||
if (System.getenv("CI") != null) {
|
||||
val debugKeystore = file("${System.getProperty("user.home")}/.android/debug.keystore")
|
||||
storeFile = debugKeystore
|
||||
storePassword = "android"
|
||||
keyAlias = "androiddebugkey"
|
||||
keyPassword = "android"
|
||||
} else {
|
||||
throw GradleException(
|
||||
"release.jks 不存在,且当前不是 CI 环境。\n" +
|
||||
"正式 Release 构建需要 release.jks 密钥库文件。\n" +
|
||||
"如需本地验证编译,请设置环境变量 CI=true 或使用 assembleDebug。"
|
||||
)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Loading…
Reference in New Issue
Block a user