Repository navigation
Releases: AssetLib/sdk-android
Release list
v0.5.0-preview.1
- Adds short looping video.
AssetClient.resolveVideo(ref)returnsResolvedVideo(sourceREMOTE,CACHEorPOSTER,sequence,message,file,width,height,durationMs,frameRate) for a placement's base slot.resolvenever downloads a clip. Only the latest accepted release downloads; retained releases are cache-only. As for Lottie animations, a missing current clip returnsPOSTER, and a current clip that cannot be used first recovers from the newest verified cached clip of an earlier release. Every use, including each cache read, checks the signed length and SHA-256 and a bounded header walk (ftypfirst,moovbefore the firstmdat, nomoof, anavc1sample entry at the signed size). Any failure returnsPOSTER, and the app shows the ordinary image or its bundled fallback. - Validates
videoSchemaVersionandvideo. The version, when present, must be exactly 1 (null or any other value rejects the manifest);videowithout it, on a variant cell, or besideanimationrejects the manifest. The descriptor must bemp4/h264-loop-v1/video/mp4with a lowercase hexsha256, 1–4,194,304bytes, evenwidthandheightof 16–1280 with at most 921,600 pixels in exactly the slot's aspect ratio, integerdurationMs1,000–10,000, a finite numericframeRate1–30, and the exact same-origin path/api/delivery/{orgId}/{appId}/assets/{assetId}/videos/{sha256}.animationSchemaVersionstays ignored. FileAssetStorageimplements the newAssetVideoStorageand keeps clips as<sha256>.mp4incacheDir, within the existing 50 MiB / 100-entry budget and least-recently-used eviction. Custom storage without it getsPOSTER. AddsLimits.VIDEO_BYTES(4 MiB) andAssetVideoSource.AssetTransportgainsget(url, maxBytes, accept), which defaults to the two-argument call, and the client now names the media type for every request:application/json, the candidate's own image type (PNG renditions sendimage/png, notimage/webp), orvideo/mp4.HttpsTransportgainsvideoTimeoutMillis(default 30,000, allowed 20–30,000) forvideo/mp4calls;HttpsTransport(timeoutMillis)still compiles.- The clip download runs outside the client's mutex, so a slow clip does not hold up image resolution. The cache no longer evicts the entry it has just written when modification times tie.
- No player dependency: the README shows Media3 1.11.x in the app. Not verified on an emulator or a device.
- Vendors the shared corpus with 27 video manifests (142 signed manifest cases),
video.jsonand theloop.mp4clip fixtures.
Recompile consuming applications when replacing the AAR. New public types (ResolvedVideo, AssetVideoSource, AssetVideoStorage), the new AssetTransport method and the HttpsTransport constructor change JVM signatures.
- Code generation rejects a group or member named
AppAssets,AssetRef,AssetAccessibilityorAssetRendering, as the Swift generator does for its own generated names.AssetRenderingproduced Kotlin that did not compile when the catalog had a template placement; the other three shadowed the generated root object or the imported SDK types. - Code generation rejects two groups that differ only in case (their class files overwrite each other on case-insensitive file systems, so one object is missing at run time) and two members of one group that compile to the same JVM getter, such as
coastandCoast, which did not compile. - A package segment that is a Kotlin hard keyword, such as
isorfun, is escaped with backticks; the unescapedpackageline did not compile. - Any other catalog generates byte-identical output. SDK sources and the AAR are unchanged.
Validation on October 11, 2026: codegen tests (5), 114 JVM unit tests with the optional hosted test skipped, lint, and the release build passed (./gradlew :sdk:testDebugUnitTest :sdk:lint :sdk:assembleRelease, JDK 17). assetlib-android-0.5.0-preview.1.aar SHA-256 b31e8508e7e039c1920ae80e944edc606283d0272f09d092d039236cc8333039 (macOS build). No emulator or device run, and no Media3 playback, is claimed. See VERIFICATION.md.
AAR SHA-256: b31e8508e7e039c1920ae80e944edc606283d0272f09d092d039236cc8333039 assetlib-android-0.5.0-preview.1.aar
v0.4.0-preview.1
- Adds tintable icons.
AssetRefgainsrendering: AssetRendering = AssetRendering.Originalas its last parameter;AssetRenderingisOriginalorTemplate. - Reads an optional
renderingstring on signed placements and variant cells; state members stay ignored. A malformed value (null, a non-string, or anything outside^[a-z][a-z0-9-]{0,31}$) rejects the manifest. A well-formed value this client does not know is kept. - Uses a descriptor only when its rendering equals the reference's (absent means original), checked on the selected appearance or arm cell. A mismatch or unknown value is handled like incompatible dimensions: that release's artwork is never read from the cache or downloaded, retained releases follow the same rule, and with no compatible artwork the result is
BUNDLE. Other placements are unaffected. - Code generation reads catalog
rendering:"template"generatesrendering = AssetRendering.Template,"original"or no field generates byte-identical output, and any other value fails. - No Compose dependency is added: the SDK returns the mask
Bitmapand the app tints it. The README showsIconwithLocalContentColor, a VectorDrawable fallback, andtargetPixelsat logical size × density. - Vendors the shared corpus with 15 rendering manifests (115 signed manifest cases) and 10 rendering resolution cases.
Recompile consuming applications and their generated references when replacing the AAR. The new AssetRef parameter keeps Kotlin source call sites compiling, but changes its JVM constructor, copy, and component signatures.
Validation on October 9 and 10, 2026: codegen tests (3), 102 JVM unit tests with the optional hosted test skipped, lint, and the release build passed (./gradlew :sdk:testDebugUnitTest :sdk:lint :sdk:assembleRelease, JDK 17). assetlib-android-0.4.0-preview.1.aar SHA-256 03d55eaa1975fe86494fb2f65e69e0ad7ad3f5a60d492f02d3c06bf3bdc9a98a (macOS build; CI on the tag uploads a Linux build for comparison). No emulator or device run. See VERIFICATION.md.
AAR SHA-256: 03d55eaa1975fe86494fb2f65e69e0ad7ad3f5a60d492f02d3c06bf3bdc9a98a assetlib-android-0.4.0-preview.1.aar
v0.3.1-preview.1
0.3.1-preview.1
Android 8.0 / API 26+. Download assetlib-android-0.3.1-preview.1.aar, verify it against SHA256SUMS (SHA-256 d3f725c1270987ae06da4f5f9cf0673e165f2b2fd7449537adfff367460a1bc3), and add the exact dependencies listed in the README; no Maven Central publication is claimed. Public configurations from the hosted console are unaffected.
- Rejects public configuration JSON over 4096 UTF-8 bytes, including unknown fields; the previous limit was 8192 bytes.
- Rejects duplicate exact-PEM pins and sets outside 1–16 keys. Every pin remains an Ed25519 SPKI PEM of at most 256 UTF-8 bytes.
- Rejects
keyIdwithout an explicitpinnedPublicKey, including when the ID matches the first set member. Known fields reject explicit nulls; optionalkeyIdsmust match the pin IDs in length and order. A single pin supplied alongside a set must belong to that set. - Runs all 43 generated shared public-config cases and 39 pinned-envelope expectations, including a trusted set member other than the single pin and an untrusted signer. Set-only configurations remain supported.
- Keeps accepted configurations within the JSON bound when serialized again. Near the limit,
toJson()omits redundant derived IDs and the duplicate first pin while preserving every ordered trusted pin and any explicit non-first single pin. - Restores the instrumented
AccessibilitySemanticsTest, its debug-only host activity and manifest, and the instrumentationtargetSdksetting, which were missing frommainwhen 0.3.0-preview.1 was tagged. Test-only; release sources are unchanged. - The CI artifact is named
assetlib-android-releaseinstead of carrying a stale version.
Validation on October 9, 2026: codegen tests (2), 98 JVM unit tests with the optional hosted test skipped, lint, and the release build passed. See VERIFICATION.md.
No emulator or device run is claimed for this patch; the configuration changes are covered by the JVM tests.
v0.3.0-preview.1
0.3.0-preview.1
Android 8.0 / API 26+. Download assetlib-android-0.3.0-preview.1.aar, verify it against SHA256SUMS, and add the exact dependencies listed in the README; no Maven Central publication is claimed.
- Accepts a
stagingenvironment in the public configuration with the environment-scoped manifest path. - Validates the additive
variantSchemaVersion: 1extension with every rule of the shared contract: declared appearance and arm values, no duplicate coordinates, cell images checked like slot images, cell states ignored. - Resolves appearance and arm cells in the fixed order arm plus appearance, arm only, appearance only, then the legacy cell, never borrowing across arms; resolved assets report
appearance,arm, andarmSource; cache entries key on the selected cell. - Adds an optional
decidecallback for the arm, run outside the mutex with a bounded wait; afterwards the client resyncs durable state, returns the bundled result when storage fails to revalidate, and reconciles against the current accepted release before any selection or download. - Derives the storage namespace from origin, org, app, and environment only, with a one-time verified migration from the previous formula.
Validation: 54 JVM tests with one optional hosted test skipped, lint clean, against the shared corpus of 100 signed manifest cases and 18 resolution entries.
a80744898801350032b71aa9241a7aba8344f333ef3360f22310d08c59ab2d20 assetlib-android-0.3.0-preview.1.aar
0.2.1-preview.1
Optional localized accessibility descriptions now follow the signed artwork version through download, cache, retained-release fallback, and offline restart. Bundled artwork has separately declared descriptions; apps keep ownership of decorative images and action labels.
Recompile consuming apps when updating the AAR: optional constructor fields preserve Kotlin source call sites but change JVM signatures. There is no new runtime or Compose dependency.
Validation: all 82 scoped signed manifest cases; 23 JVM tests passed and one optional hosted test skipped; two code-generation tests passed; lint and release assembly passed. Five Android API 36.1 emulator tests passed, including native accessibility-tree checks. Manual TalkBack and physical-device acceptance remain unverified.
GitHub CI passed at 523b1eba0e641cf2b2910c8ef4e5a744e4167441: https://github.com/AssetLib/sdk-android/actions/runs/37729645796. Its Linux-built AAR exactly matches the local artifact.
AAR SHA-256: 60a8ebe267f7aab6ef72e35546c97270008cdd7674dd17cc975f3395c85539c7.
This is a developer preview distributed as a standalone AAR with a checksum file. No Maven Central publication or production support commitment is claimed.
0.2.0-preview.1 — PNG and sized renditions
0.2.0-preview.1
- Recognizes the signed rendition-schema-1 extension without breaking legacy WebP manifests. Rejects malformed or unknown explicit extensions, including null arrays and versions.
- Selects PNG/WebP according to an explicit target pixel size; defaults to logical reference dimensions. Deterministic area/byte/hash ordering, bounded per-candidate downloads, then legacy WebP fallback. Historical candidates remain cache-only.
- Validates actual raster MIME, declared rendition dimensions, full native decode, hash/byte length, and aspect/pixel bounds before caching or rendering. Returns selected MIME, pixel dimensions, asset ID, hash, source, and rendered release sequence.
- Preserves origin/path binding, pinned signatures, durable high-water marks, same-sequence equivocation checks, concurrent storage guards, and corrupt-state fail-closed behavior.
- SVG candidates are validated but skipped on Android. No native SVG renderer or Compose dependency is added; the demo uses a normal BitmapPainter adapter.
API change: AssetClient's custom decoder now returns AssetImageInfo? instead of using the earlier Boolean validateImage hook. Default native decoding is enabled even when constructing AssetClient directly. Apps using the standard factory need no custom decoder.
Validation: 65 shared signed manifest cases; target ranking, PNG metadata, candidate failure, legacy fallback, historical cache-only and anti-replay unit checks; native PNG/WebP decode and offline restart on Android API 36.1 emulator. See the test reports for exact run counts. Preview status remains; no all-device performance or production support guarantee.
Android SDK 0.1.0-preview.1
First public native Kotlin developer preview for Assetlib. Android 8.0 / API 26+, ordinary Android bitmaps and Compose images, MIT licensed.
Includes generated typed placement references, pinned Ed25519 verification, scoped and bounded HTTPS downloads, SHA-256 verification, durable release sequencing, atomic app-private storage, verified cache, and bundled fallback.
Download the AAR and verify it with SHA256SUMS. Runtime dependencies are declared in the README; this AAR does not shade or bundle them. The native travel demo downloads this exact artifact and verifies its pinned digest. No Maven Central publication is claimed.
Validation: 14 JVM tests passed locally, including the 43-case shared manifest corpus, integer-number interoperability, and a read-only hosted release-3 download followed by an independent offline cache restart. Two emulator tests passed for real Android WebP decoding, logical dimensions, invalid-image rejection, and offline restart. Lint, release AAR assembly, and offline code-generation checks passed. These checks do not establish behavior across all physical devices.
This preview handles still WebP artwork. Figma, analytics, experiments, automatic screen discovery, push updates, and key rotation are not included. It is not a production-readiness or Play Store approval claim.