Skip to content

security: harden public mobile release credentials - #33

Merged
Harzva merged 1 commit into
main-devfrom
codex/public-release-secret-hardening
Aug 6, 2026
Merged

security: harden public mobile release credentials#33
Harzva merged 1 commit into
main-devfrom
codex/public-release-secret-hardening

Conversation

@Harzva

@Harzva Harzva commented Aug 6, 2026

Copy link
Copy Markdown
Owner

Summary

  • remove raw provider keys, relay bearer tokens, and OAuth client secrets from public Android/iOS build workflows
  • add a fail-closed workflow credential policy and tests
  • bump the public candidate to v0.1.77+67 and document withdrawal of the former v0.1.76 official APK
  • retain public relay URL/OAuth client ID/redirect URI configuration and BYOK secure-storage flows

Verification

  • public credential policy: 4 workflows pass
  • Python policy + physical QA runner tests: 16 passed
  • MobileCore client/adaptive/network/cloud approval Flutter tests: 41 passed
  • targeted Flutter analyze: exit 0 (existing warnings/info only)
  • Semgrep p/secrets: 0 findings across 1097 tracked files
  • clean local pureRelease: v0.1.77+67; standard key/JWT/Bearer patterns: 0
  • Android 16 arm64 emulator clean install: versionCode 67, UI v0.1.77, no fatal markers

Physical Android thermal/background and verified Omni audio gates remain open and are not claimed by this PR.

@Harzva
Harzva merged commit d031692 into main-dev Aug 6, 2026
@Harzva
Harzva deleted the codex/public-release-secret-hardening branch August 6, 2026 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant