Skip to content

Update approov-service-httpsurlconn to 3.5.4 and the Shapes app build - #7

Merged
charlesoj6205 merged 2 commits into
masterfrom
feature/update-service-layer-versions
Oct 2, 2026
Merged

charlesoj6205 merged 2 commits into
masterfrom
feature/update-service-layer-versions

Conversation

@charlesoj6205

@charlesoj6205 charlesoj6205 commented Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

Changes

  • io.approov:service.httpsurlconn 3.5.3 → 3.5.4 in README.md and SHAPES-EXAMPLE.md.
  • Commit 5408086 updates the Shapes app build, because 3.5.4 does not build on the old setup:
    • Android Gradle plugin 7.1.1 → 8.9.0, Gradle 7.2 → 8.11.1.
    • namespace "io.approov.shapes" added, and the manifest package attribute removed.
    • minSdkVersion 21 → 23, compileSdkVersion 31 → 35, targetSdkVersion 31 → 34.
    • Core library desugaring enabled, with desugar_jdk_libs:2.1.4.
    • R8 -dontwarn rules for com.google.android.gms.tasks.** and com.google.android.play.core.integrity.**.
  • README.md documents minSdk 23, desugaring and the R8 rules. SHAPES-EXAMPLE.md documents the Android Studio and JDK 17 requirements.

Why

Service layer 3.5.4 changed two things that 3.5.3 did not have:

  • Its manifest declares minSdkVersion="23" (3.5.3: 21).
  • Its AAR metadata declares coreLibraryDesugaringEnabled=true with desugar_jdk_libs:2.1.4 (3.5.3: false).

With the old setup, the guide's dependency line fails in the manifest merge (minSdkVersion 21 cannot be smaller than version 23). With minSdk 23, D8 in Android Gradle plugin 7.1.1 and 7.4.2 crashes on the 3.5.4 jar with a NullPointerException. Android Gradle plugin 8.9.0 with desugaring builds it.

The other changes follow from the Android Gradle plugin 8 upgrade:

  • R8 rules: Approov SDK 3.5.1 and 3.5.3 refer to optional Google Play services and Play Integrity classes. Android Gradle plugin 7 only warned about missing classes. Version 8 stops the release build. The merged kotlin-okhttp quickstart has the same release build failure.
  • targetSdk 34: the new lint fails release builds for targetSdk 31 (ExpiredTargetSdkVersion). targetSdk 35 enforces edge-to-edge layout, which put the buttons under the gesture bar. targetSdk 34 passes lint and keeps the layout unchanged.

Testing

Build Result
Unmodified branch + guide dependency (before the fix) Fails: minSdkVersion 21 cannot be smaller than version 23
Shipped app, debug and release Pass
App with the guide dependency and Approov code enabled, debug and release Pass

On an Android 17 emulator, the app with Approov enabled initialized SDK 3.5.3(7361), fetched a token and sent the request to /v3/shapes. The layout is correct (screenshot checked). The test used a fake config string, so it did not get a valid token.

The gradle.build typo in the docs is not fixed here. approov/core-project-approov#657 tracks it.

Refs approov/core-project-approov#644

🤖 Generated with Claude Code

Point the quickstart at the current release on Maven Central, and align
the Approov SDK reference with the version the service layer actually
resolves transitively (verified against the service POM).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the documented Approov HttpsUrlConnection service layer dependency version to match the latest published release, ensuring new users copy/paste the correct Maven coordinate.

Changes:

  • Bump io.approov:service.httpsurlconn from 3.5.3 to 3.5.4 in README.md.
  • Bump io.approov:service.httpsurlconn from 3.5.3 to 3.5.4 in SHAPES-EXAMPLE.md.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
README.md Updates the Gradle dependency snippet to 3.5.4.
SHAPES-EXAMPLE.md Updates the Shapes example Gradle dependency snippet to 3.5.4.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Service layer 3.5.4 needs minSdk 23 and core library desugaring. The
Shapes app used minSdk 21 and Android Gradle plugin 7.1.1, so the guide
dependency failed in the manifest merge, and D8 crashed on the 3.5.4 jar.

- Upgrade Android Gradle plugin 7.1.1 -> 8.9.0 and Gradle 7.2 -> 8.11.1.
- Add namespace and remove the manifest package attribute.
- Raise minSdk 21 -> 23, compileSdk 31 -> 35 and targetSdk 31 -> 34.
  targetSdk 34 passes the lint check for release builds and keeps the
  layout unchanged, because targetSdk 35 enforces edge-to-edge.
- Enable core library desugaring with desugar_jdk_libs 2.1.4.
- Add R8 -dontwarn rules for the optional Google Play services and Play
  Integrity classes that the Approov SDK refers to.
- Document minSdk 23, desugaring, the R8 rules and the Android Studio
  and JDK requirements in README.md and SHAPES-EXAMPLE.md.

Tested: debug and release builds pass, with and without the guide
dependency. On an Android 17 emulator, the app initialized SDK 3.5.3 and
fetched a token for the v3 endpoint.

Refs approov/core-project-approov#644

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@charlesoj6205 charlesoj6205 changed the title Update Approov service layer to latest published versions Update approov-service-httpsurlconn to 3.5.4 and the Shapes app build Sep 29, 2026
@charlesoj6205
charlesoj6205 requested a balanced review from Copilot October 2, 2026 13:47

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation and build configuration consistently satisfy the verified requirements of service version 3.5.4 and Android Gradle plugin 8.9.0.

Review effort: Balanced
Findings: None

@charlesoj6205
charlesoj6205 merged commit 01c42bb into master Oct 2, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants