Resource exclusion pattern org/ silently strips resources from all org.* library packages
Severity: High
File: app/build.gradle.kts:413
The packaging resources exclusion block contains:
resources {
excludes += "META-INF/"
excludes += "kotlin/"
excludes += "org/"
excludes += ".properties"
}
The "org/" pattern is a prefix match against the resource path inside any dependency JAR/AAR. Any library that ships resources under org/ (e.g. org/apache/, org/xmlpull/, org/bouncycastle/ resource files, org/intellij/lang/annotations/) will have those resources silently stripped from the APK.
Why it matters
This is an overly broad exclusion that can cause runtime ClassNotFoundException, FileNotFoundException, or missing-resource crashes in any library whose resources live under org/. If the intent is to exclude only a specific package (e.g. BouncyCastle's pre-computed tables already handled at line 418), the pattern should be narrowed to the specific path like org/bouncycastle/ rather than the entire org/ tree. The same concern applies to the .properties substring match on line 414, which will exclude any file ending in .properties from any dependency — not just META-INF.
Resource exclusion pattern
org/silently strips resources from allorg.*library packagesSeverity: High
File:
app/build.gradle.kts:413The packaging resources exclusion block contains:
resources { excludes += "META-INF/" excludes += "kotlin/" excludes += "org/" excludes += ".properties" }The
"org/"pattern is a prefix match against the resource path inside any dependency JAR/AAR. Any library that ships resources underorg/(e.g.org/apache/,org/xmlpull/,org/bouncycastle/resource files,org/intellij/lang/annotations/) will have those resources silently stripped from the APK.Why it matters
This is an overly broad exclusion that can cause runtime
ClassNotFoundException,FileNotFoundException, or missing-resource crashes in any library whose resources live underorg/. If the intent is to exclude only a specific package (e.g. BouncyCastle's pre-computed tables already handled at line 418), the pattern should be narrowed to the specific path likeorg/bouncycastle/rather than the entireorg/tree. The same concern applies to the.propertiessubstring match on line 414, which will exclude any file ending in.propertiesfrom any dependency — not just META-INF.