Skip to content

OpenVM bootstrap and protected APK signing handoff #1

Description

@MatDayProjects

Scope

Build OpenVM from an empty checkout as a local-first open-source Android VM control plane, add profile/image-reference management, and provide a protected GitHub Actions release-signing path.

Current verification state

🏃 running — the hosted signing workflow is running for commit ef523824b3ea4cc39f14526078c6c98cf61eab39.

Local evidence already recorded:

  • ./gradlew testDebugUnitTest assembleDebug lintDebug passed.
  • ./gradlew assembleDebugAndroidTest passed; the instrumentation APK compiled, but no Android emulator was available to execute it.
  • ./gradlew assembleRelease bundleRelease passed; release APK/AAB outputs are unsigned before the protected CI signing step.
  • actionlint -shellcheck= passed structural workflow validation. The Windows host has no shellcheck, so run-block shell analysis remains a hosted-CI gate.
  • Debug APK certificate verification with apksigner verify --verbose --print-certs passed.

The application surface has not been captured because no emulator/device is available in this workspace; no unrelated screenshot is being presented as proof.

Handoff

粵語摘要

OpenVM 由空白 checkout 起步,已經有本地 VM 設定檔、映像參考、歷史、設定頁、regex 搜尋同受保護嘅 GitHub Actions APK 簽名流程。local checks 已過,hosted signing run 仲做緊;冇 Android emulator,所以唔會扮有 screenshot 證明畫面。

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions