Update approov-service-httpsurlconn to 3.5.4 and the Shapes app build - #7
Merged
Merged
Conversation
Point the quickstart at the current release on Maven Central, and align the Approov SDK reference with the version the service layer actually resolves transitively (verified against the service POM). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Pull request overview
Updates the documented Approov HttpsUrlConnection service layer dependency version to match the latest published release, ensuring new users copy/paste the correct Maven coordinate.
Changes:
- Bump
io.approov:service.httpsurlconnfrom 3.5.3 to 3.5.4 inREADME.md. - Bump
io.approov:service.httpsurlconnfrom 3.5.3 to 3.5.4 inSHAPES-EXAMPLE.md.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| README.md | Updates the Gradle dependency snippet to 3.5.4. |
| SHAPES-EXAMPLE.md | Updates the Shapes example Gradle dependency snippet to 3.5.4. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Service layer 3.5.4 needs minSdk 23 and core library desugaring. The Shapes app used minSdk 21 and Android Gradle plugin 7.1.1, so the guide dependency failed in the manifest merge, and D8 crashed on the 3.5.4 jar. - Upgrade Android Gradle plugin 7.1.1 -> 8.9.0 and Gradle 7.2 -> 8.11.1. - Add namespace and remove the manifest package attribute. - Raise minSdk 21 -> 23, compileSdk 31 -> 35 and targetSdk 31 -> 34. targetSdk 34 passes the lint check for release builds and keeps the layout unchanged, because targetSdk 35 enforces edge-to-edge. - Enable core library desugaring with desugar_jdk_libs 2.1.4. - Add R8 -dontwarn rules for the optional Google Play services and Play Integrity classes that the Approov SDK refers to. - Document minSdk 23, desugaring, the R8 rules and the Android Studio and JDK requirements in README.md and SHAPES-EXAMPLE.md. Tested: debug and release builds pass, with and without the guide dependency. On an Android 17 emulator, the app initialized SDK 3.5.3 and fetched a token for the v3 endpoint. Refs approov/core-project-approov#644 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
io.approov:service.httpsurlconn3.5.3 → 3.5.4 inREADME.mdandSHAPES-EXAMPLE.md.namespace "io.approov.shapes"added, and the manifestpackageattribute removed.minSdkVersion21 → 23,compileSdkVersion31 → 35,targetSdkVersion31 → 34.desugar_jdk_libs:2.1.4.-dontwarnrules forcom.google.android.gms.tasks.**andcom.google.android.play.core.integrity.**.README.mddocuments minSdk 23, desugaring and the R8 rules.SHAPES-EXAMPLE.mddocuments the Android Studio and JDK 17 requirements.Why
Service layer 3.5.4 changed two things that 3.5.3 did not have:
minSdkVersion="23"(3.5.3: 21).coreLibraryDesugaringEnabled=truewithdesugar_jdk_libs:2.1.4(3.5.3: false).With the old setup, the guide's dependency line fails in the manifest merge (
minSdkVersion 21 cannot be smaller than version 23). With minSdk 23, D8 in Android Gradle plugin 7.1.1 and 7.4.2 crashes on the 3.5.4 jar with aNullPointerException. Android Gradle plugin 8.9.0 with desugaring builds it.The other changes follow from the Android Gradle plugin 8 upgrade:
ExpiredTargetSdkVersion). targetSdk 35 enforces edge-to-edge layout, which put the buttons under the gesture bar. targetSdk 34 passes lint and keeps the layout unchanged.Testing
minSdkVersion 21 cannot be smaller than version 23On an Android 17 emulator, the app with Approov enabled initialized SDK
3.5.3(7361), fetched a token and sent the request to/v3/shapes. The layout is correct (screenshot checked). The test used a fake config string, so it did not get a valid token.The
gradle.buildtypo in the docs is not fixed here. approov/core-project-approov#657 tracks it.Refs approov/core-project-approov#644
🤖 Generated with Claude Code