androguard 4.1.4 raises 'NoOverwriteDict object has no attribute append' in
parse_v2_v3_signature when fdroidserver extracts the signer cert — this broke the
self-hosted F-Droid publish from v0.4.2 on. 4.1.3 (which shipped v0.3.2–v0.4.1)
parses our re-signed v1+v2-only APK cleanly; verified locally with
fdroidserver.common.get_first_signer_certificate.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The self-hosted F-Droid repo (https://dzianisv.github.io/opencode-mobile/fdroid/repo)
has been stuck at v0.4.1 because publish-fdroid crashed in androguard parsing the
CI APK's v2+v3 signature block pair ('NoOverwriteDict' object has no attribute
'append'). Force v1+v2-only signing: gradle flags for local builds, plus a
deterministic apksigner re-sign step in the workflow (expo prebuild regenerates
build.gradle, so the workflow step is the real guarantee). Bump to v0.4.3 /
versionCode 5 so a fresh tag re-runs the publish with the verified bug fixes
(#10 scope fixes, send-error fix) included.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Reproduced locally against the v0.4.2 APK: androguard 4.0.x fails resource
parsing ('res1 must be zero!'), 4.1.0/4.1.1 fail signature parsing
('NoOverwriteDict' object has no attribute 'append'), and 4.1.4 parses both
cleanly. fdroidserver 2.4.4's own resolver pulls a buggy 4.1.x, so pin 4.1.4.
Pinning fdroidserver 2.4.4 hit androguard parse bugs on modern aapt2 APKs
(4.1+: NoOverwriteDict.append; 4.0.x: 'res1 must be zero!'). Upgrade to latest
fdroidserver which ships a compatible androguard.
fdroidserver 2.4.4 + androguard 4.1+ crashes in 'fdroid update' with
"'NoOverwriteDict' object has no attribute 'append'" while parsing the APK
v2/v3 signature. Pin androguard>=4.0,<4.1 to restore the self-hosted F-Droid
repo publish.