fix(ci): pin androguard==4.1.3 for F-Droid publish (4.1.4 crashes on signer cert)

androguard 4.1.4 raises 'NoOverwriteDict object has no attribute append' in
parse_v2_v3_signature when fdroidserver extracts the signer cert — this broke the
self-hosted F-Droid publish from v0.4.2 on. 4.1.3 (which shipped v0.3.2–v0.4.1)
parses our re-signed v1+v2-only APK cleanly; verified locally with
fdroidserver.common.get_first_signer_certificate.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
engineer
2026-06-02 01:29:59 -07:00
parent 821672048c
commit eea84a3f35

View File

@@ -92,12 +92,13 @@ jobs:
"$APKSIGNER" verify -v "$APK" | grep -i "Verified using" || true "$APKSIGNER" verify -v "$APK" | grep -i "Verified using" || true
- name: Install fdroidserver - name: Install fdroidserver
# androguard version matters: 4.0.x crashes parsing our APK resources # androguard version matters. 4.1.4 crashes extracting the signer cert
# ("res1 must be zero!"); 4.1.0/4.1.1 crash on the signature block # ("'NoOverwriteDict' object has no attribute 'append'" in
# ("'NoOverwriteDict' object has no attribute 'append'"). androguard 4.1.4 # parse_v2_v3_signature) — this is what broke the publish from v0.4.2 on.
# fixes both — verified locally against the v0.4.2 APK. fdroidserver's own # 4.1.3 is the version that successfully published v0.3.2–v0.4.1 and parses
# resolver picks a buggy 4.1.x, so pin androguard explicitly. # our (v1+v2-only, re-signed above) APK cleanly — verified locally against
run: pip install "fdroidserver==2.4.4" "androguard==4.1.4" # the release APK via fdroidserver.common.get_first_signer_certificate.
run: pip install "fdroidserver==2.4.4" "androguard==4.1.3"
- name: Setup F-Droid repo - name: Setup F-Droid repo
id: fdroid-setup id: fdroid-setup