From 52bf201e09f37a4ff7b60912cfb97779863a4bba Mon Sep 17 00:00:00 2001 From: Henrique Velloso Date: Wed, 14 Jan 2026 00:46:10 -0300 Subject: [PATCH] Add GitHub Actions workflow for reproducible APK proof, enabling automated verification of build reproducibility using Docker. This includes steps for checking out the repository, running scripts, and uploading artifacts. --- .github/workflows/repro.yml | 41 +++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) create mode 100644 .github/workflows/repro.yml diff --git a/.github/workflows/repro.yml b/.github/workflows/repro.yml new file mode 100644 index 0000000..fb73be5 --- /dev/null +++ b/.github/workflows/repro.yml @@ -0,0 +1,41 @@ +name: Reproducible APK Proof + +on: + workflow_dispatch: + +jobs: + repro: + runs-on: ubuntu-22.04 + timeout-minutes: 90 + permissions: + contents: read + + steps: + - name: Checkout + uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Show runner info + run: | + uname -a + lscpu | sed -n '1,30p' + docker version + docker info | sed -n '1,80p' + + - name: Make scripts executable + run: | + chmod +x repro/prove_repro.sh || true + chmod +x repro/build_in_container.sh || true + + - name: Run reproducibility proof (Docker) + run: | + bash repro/prove_repro.sh + + - name: Upload artifacts (.repro_out) + if: always() + uses: actions/upload-artifact@v4 + with: + name: repro-out-${{ github.sha }} + path: .repro_out + if-no-files-found: warn