Skip to content

Resource exclusion pattern org/ silently strips resources from all org.* library packages #21

Description

@yutongwong

Resource exclusion pattern org/ silently strips resources from all org.* library packages

Severity: High
File: app/build.gradle.kts:413

The packaging resources exclusion block contains:

resources {
    excludes += "META-INF/"
    excludes += "kotlin/"
    excludes += "org/"
    excludes += ".properties"
}

The "org/" pattern is a prefix match against the resource path inside any dependency JAR/AAR. Any library that ships resources under org/ (e.g. org/apache/, org/xmlpull/, org/bouncycastle/ resource files, org/intellij/lang/annotations/) will have those resources silently stripped from the APK.

Why it matters

This is an overly broad exclusion that can cause runtime ClassNotFoundException, FileNotFoundException, or missing-resource crashes in any library whose resources live under org/. If the intent is to exclude only a specific package (e.g. BouncyCastle's pre-computed tables already handled at line 418), the pattern should be narrowed to the specific path like org/bouncycastle/ rather than the entire org/ tree. The same concern applies to the .properties substring match on line 414, which will exclude any file ending in .properties from any dependency — not just META-INF.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions