From a663ef7f1b1e42cd744972d1a2ccb1119656f1ae Mon Sep 17 00:00:00 2001 From: atsunatsu Date: Sat, 5 Sep 2026 07:57:33 +0800 Subject: [PATCH] build: read release signing credentials from local.properties/env instead of hardcoding Passwords for the release keystore were committed in plaintext to a public repo. Move them to gitignored local.properties with an environment-variable fallback. Keystore file itself stays in $HOME. --- app/build.gradle.kts | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/app/build.gradle.kts b/app/build.gradle.kts index 649b3400..0632f81e 100644 --- a/app/build.gradle.kts +++ b/app/build.gradle.kts @@ -1,7 +1,19 @@ +import java.io.FileInputStream +import java.util.Properties + plugins { alias(libs.plugins.convention.applicationPlugin) } +// Release signing credentials live in local.properties (gitignored) or +// environment variables — never hardcode passwords in VCS. +val releaseProps = Properties().apply { + val propsFile = rootProject.file("local.properties") + if (propsFile.exists()) FileInputStream(propsFile).use { load(it) } +} +fun releaseCred(name: String): String = + releaseProps.getProperty(name) ?: System.getenv(name) ?: "" + android { namespace = libs.versions.packageName.get() defaultConfig { @@ -11,9 +23,9 @@ android { signingConfigs { create("release") { storeFile = file(System.getProperty("user.home") + "/my-release-key.jks") - storePassword = "look4sat123" - keyAlias = "look4sat" - keyPassword = "look4sat123" + storePassword = releaseCred("RELEASE_STORE_PASSWORD") + keyAlias = releaseCred("RELEASE_KEY_ALIAS").ifEmpty { "look4sat" } + keyPassword = releaseCred("RELEASE_KEY_PASSWORD") } } buildTypes {