Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
enable built-in gradle dependency verification
This fully replaces gradle-witness and goes far beyond what it offered. As far as I can tell, this actually will verify every single artifact that gradle downloads and uses. This was generated by first copying the existing one in fdroidclient, then running two passes to get both the PGP and the SHA256 info: ./gradlew --write-verification-metadata pgp,sha256 build --export-keys ./gradlew --write-verification-metadata sha256 build Thanks to @vlsi who made me aware of this, and helped make it possible. fdroid/fdroidclient!837
- Loading branch information
e5d1cc6
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
👍