ci(gradle): pin Gradle distribution against published SHA-256 #450

Merged
JMR-dev merged 1 commits from ci-pin-gradle-dist-sha into main 2026-07-08 18:39:23 +00:00
JMR-dev commented 2026-07-08 17:05:03 +00:00 (Migrated from github.com)

What

Pin the Gradle distribution against its published SHA-256 via distributionSha256Sum in gradle-wrapper.properties.

Why

Follows the CI-download-integrity discussion. The wrapper had only validateDistributionUrl=true (URL-shape check, not content), so gradle-9.6.0-bin.zip was the one genuinely unpinned download in CI. cmdline-tools is already SHA-256-pinned (#389); SDK/emulator packages are sdkmanager-SHA-1-verified against Google's manifest. This closes the Gradle gap.

distributionSha256Sum is enforced natively by the Gradle wrapper — any mismatch fails the build closed. Value is bbaeb2fef8710818cf0e261201dab964c572f92b942812df0c3620d62a529a01 (Gradle's published .sha256). Self-validating: if the pin were wrong, this PR's own build would fail.

## What Pin the Gradle distribution against its published **SHA-256** via `distributionSha256Sum` in `gradle-wrapper.properties`. ## Why Follows the CI-download-integrity discussion. The wrapper had only `validateDistributionUrl=true` (URL-shape check, **not** content), so `gradle-9.6.0-bin.zip` was the one genuinely **unpinned** download in CI. cmdline-tools is already SHA-256-pinned (#389); SDK/emulator packages are sdkmanager-SHA-1-verified against Google's manifest. This closes the Gradle gap. `distributionSha256Sum` is enforced natively by the Gradle wrapper — any mismatch fails the build closed. Value is `bbaeb2fef8710818cf0e261201dab964c572f92b942812df0c3620d62a529a01` (Gradle's published `.sha256`). **Self-validating**: if the pin were wrong, this PR's own build would fail.
mergify[bot] commented 2026-07-08 17:34:19 +00:00 (Migrated from github.com)

Merge Queue Status

This pull request spent 56 minutes 39 seconds in the queue, including 50 minutes 56 seconds running CI.

Waiting for
  • check-success = CI passed
  • any of: [🛡 GitHub branch protection]
    • check-neutral = CI passed
    • check-skipped = CI passed
    • check-success = CI passed
  • any of: [🛡 GitHub repository ruleset rule main]
    • check-neutral = @github-actions/CI passed
    • check-skipped = @github-actions/CI passed
    • check-success = @github-actions/CI passed
All conditions

Reason

The merge conditions cannot be satisfied due to failing checks

  • CI passed
  • Debug build
  • Unit tests
  • @github-actions/CI passed

Failing checks:

Hint

You may have to fix your CI before adding the pull request to the queue again.
If you update this pull request, to fix the CI, it will automatically be requeued once the queue conditions match again.
If you think this was a flaky issue instead, you can requeue the pull request, without updating it, by posting a @mergifyio queue comment.

Tick the box to put this pull request back in the merge queue (same as @mergifyio queue).

  • Requeue this pull request
<!--- DO NOT EDIT -*- Mergify Payload -*- {"version": 1, "state": "dequeued", "queue_rule_name": "default", "queued_at": "2026-07-08T17:34:17.771439+00:00", "estimated_time_of_merge": null, "speculative_check_pr": null, "required_conditions": []} -*- Mergify Payload End -*- --> # Merge Queue Status - ✅ **Entered queue** — `2026-07-08 17:34 UTC` · Rule: `default` · triggered by merge protections - ❌ **Checks failed** · on draft #453 - 🚫 **Left the queue** — `2026-07-08 18:30 UTC` · at `7a0cc3145c1b64ce878dfcea869d87658b66325e` This pull request spent **56 minutes 39 seconds** in the queue, including **50 minutes 56 seconds** running CI. <details> <summary><strong>Waiting for</strong></summary> - [ ] `check-success = CI passed` - [ ] any of: [🛡 GitHub branch protection] - [ ] `check-neutral = CI passed` - [ ] `check-skipped = CI passed` - [ ] `check-success = CI passed` - [ ] any of: [🛡 GitHub repository ruleset rule `main`] - [ ] `check-neutral = @github-actions/CI passed` - [ ] `check-skipped = @github-actions/CI passed` - [ ] `check-success = @github-actions/CI passed` </details> <details> <summary>All conditions</summary> - [ ] `check-success = CI passed` - [ ] any of [🛡 GitHub branch protection]: - [ ] `check-neutral = CI passed` - [ ] `check-skipped = CI passed` - [ ] `check-success = CI passed` - [ ] any of [🛡 GitHub repository ruleset rule `main`]: - [ ] `check-neutral = @github-actions/CI passed` - [ ] `check-skipped = @github-actions/CI passed` - [ ] `check-success = @github-actions/CI passed` - `-conflict` - [X] #450 - `-draft` - [X] #450 - [X] `base = main` - `github-review-approved` [🛡 GitHub repository ruleset rule `main`] - [X] #450 - `label != broken` - [X] #450 - [X] any of [🛡 GitHub branch protection]: - [X] `check-success = Debug build` - [ ] `check-neutral = Debug build` - [ ] `check-skipped = Debug build` - [X] any of [🛡 GitHub branch protection]: - [X] `check-success = Unit tests` - [ ] `check-neutral = Unit tests` - [ ] `check-skipped = Unit tests` </details> ## Reason The merge conditions cannot be satisfied due to failing checks - `CI passed` - `Debug build` - `Unit tests` - `@github-actions/CI passed` Failing checks: - ❌ [CI passed](https://github.com/JMR-dev/LibreMail/actions/runs/28963243965/job/85950240994) ([job log](https://github.com/JMR-dev/LibreMail/actions/runs/28963243965/job/85950240994)) ## Hint You may have to fix your CI before adding the pull request to the queue again. If you update this pull request, to fix the CI, it will automatically be requeued once the queue conditions match again. If you think this was a flaky issue instead, you can requeue the pull request, without updating it, by posting a `@mergifyio queue` comment. Tick the box to put this pull request back in the merge queue (same as `@mergifyio queue`). - [ ] Requeue this pull request <!-- mergify:queue-control:requeue -->
Sign in to join this conversation.