2 Build Security
Dominik Schürmann edited this page 2015-06-16 00:08:40 +02:00
  1. On execution of ./gradlew build, the gradle wrapper downloads the actually required gradle version. This download is protected by SHA-256 verification integrated by us into Gradle Wrapper (see gradle/wrapper/gradle-wrapper.properties).
  2. All dependencies are either included as git submodules or downloaded from JCenter. JCenter dependencies are verified using SHA-256 by Gradle Witness (see OpenKeychain/build.gradle).

TODO?: buildscript dependency verification?