release 1.2 issues
Bruce is listed at IzzyOnDroid, where we have a per-app size limit of 30 MB. But from the previous release (0.3) with 11 MB APK size, the size of the APK now jumped to almost 50 MB – so we can no longer keep it updated. What happened there?
Further, our scanners reported
! repo/bruce.app_2.apk declares flag(s): usesCleartextTraffic
! repo/bruce.app_2.apk declares sensitive permission(s): android.permission.READ_EXTERNAL_STORAGE android.permission.MANAGE_EXTERNAL_STORAGE
If the size issue can be solved (providing per-ABI split builds, each of those APKs would be about 19 MB smaller, for example – and if you'd enable legacy compression for the native libs, even more), we'd like to make transparent why these permissions are now needed.
Thanks in advance!
Any word, @pr3y? The update was blocked here due to one more issue:
WARNING: "bruce.app_2.apk" is signed by a key that is not allowed:
0ed9a102e22c32120d588ab8f3bb841b7d4cff8dcb80cfdcb576886772e98eba
So updates are even impossible (Android would reject them due to signature mismatch). What happened to your signing key? Recommended reading: How to keep your key safe and what measures to take for the event of loss?
Sad. We had to disable updates now entirely. We were hoping that putting the app on the monthly track would give enough time to solve this issue – but if you don't even answer, @pr3y, we have no means to solve it. And without the ability of providing updates, what sense does it make to have the app in our repo?
I'll disable RB checks now as well; without us shipping the APKs, there's no sense in giving resources to that anymore either. Can of course all be reverted once this issue here has been solved.