SDKs

Maven Repository

Add the ConfigDirector Maven repository to a Gradle or Maven build to install the Android and Java SDKs, and verify the files it serves

The ConfigDirector Android and Java SDKs, and the OpenFeature providers built on them, are published to the ConfigDirector Maven repository:

https://maven.configdirector.com

Anyone can download from it, without an account or credentials. Once a version is published there it never changes: its files are never replaced or deleted.

Artifacts

ArtifactContents
com.configdirector:android-sdkThe Android SDK
com.configdirector:android-sdk-composeJetpack Compose bindings for the Android SDK
com.configdirector:android-sdk-testingTools for testing code that uses the Android SDK
com.configdirector:openfeature-android-providerThe OpenFeature Android provider
com.configdirector:server-sdkThe Java server SDK
com.configdirector:server-sdk-testingTools for testing code that uses the Java server SDK
com.configdirector:openfeature-server-providerThe OpenFeature Java provider

Older versions on Maven Central

Versions up to Android SDK 1.6.0, OpenFeature Android provider 1.2.0, Java server SDK 1.7.0 and OpenFeature Java provider 1.4.0 were published to Maven Central under older names. Newer versions are only in this repository.

Name on Maven CentralName in this repository
configdirector-androidandroid-sdk
configdirector-android-composeandroid-sdk-compose
configdirector-android-testingandroid-sdk-testing
configdirector-openfeature-android-provideropenfeature-android-provider
configdirector-server-sdkserver-sdk
configdirector-server-sdk-testingserver-sdk-testing
configdirector-openfeature-server-provideropenfeature-server-provider

To upgrade from a version on Maven Central, add the repository to your build and change the artifact names. Change all of them at once: an artifact under its old name and the same artifact under its new name contain the same classes, so they cannot be on the same classpath.

Add the repository to your build

Gradle

If your build declares its repositories in settings.gradle.kts or settings.gradle, under dependencyResolutionManagement, add the repository there. Android Studio sets up new projects this way, and their builds fail if a module's build file declares a repository.

dependencyResolutionManagement {
    repositories {
        google()
        mavenCentral()
        exclusiveContent {
            forRepository {
                maven {
                    name = "ConfigDirector"
                    url = uri("https://maven.configdirector.com")
                }
            }
            filter {
                includeGroup("com.configdirector")
            }
        }
    }
}

Otherwise, add it to the repositories block of your build file:

repositories {
    mavenCentral()
    exclusiveContent {
        forRepository {
            maven {
                name = "ConfigDirector"
                url = uri("https://maven.configdirector.com")
            }
        }
        filter {
            includeGroup("com.configdirector")
        }
    }
}

With exclusiveContent, Gradle looks for ConfigDirector artifacts only in this repository, and looks for nothing else there. Keep the other repositories your build already lists.

Maven

Add the repository to pom.xml:

pom.xml
<repositories>
  <repository>
    <id>configdirector</id>
    <url>https://maven.configdirector.com</url>
    <releases><enabled>true</enabled></releases>
    <snapshots><enabled>false</enabled></snapshots>
  </repository>
</repositories>

Dependabot

Dependabot can't reach this repository until .github/dependabot.yml declares it, even though the repository needs no credentials. Declare it so that Dependabot can open pull requests for new versions of the SDKs:

.github/dependabot.yml
version: 2
registries:
  configdirector:
    type: maven-repository
    url: https://maven.configdirector.com
updates:
  - package-ecosystem: "gradle"
    directory: "/"
    registries:
      - configdirector
    schedule:
      interval: "weekly"

For a Maven build, the package-ecosystem is "maven". If the file already has updates entries, add configdirector to the registries of each entry that covers a build using the SDKs.

Company repository managers

If your builds download their dependencies through a repository manager such as Sonatype Nexus Repository or JFrog Artifactory, rather than from public repositories directly, its administrator adds this repository once:

  1. Create a Maven proxy repository (a remote repository in Artifactory) with https://maven.configdirector.com as its URL. It only serves release versions and needs no credentials.
  2. Limit it to the com.configdirector group: in Nexus with a routing rule that allows ^/com/configdirector/.*, in Artifactory with the include pattern com/configdirector/**.
  3. Add it to the group repository (the virtual repository in Artifactory) that your builds use.

Your builds keep listing only the repository manager, and get the SDKs through it like any other dependency.

Verify what you download

Every jar, AAR and POM in the repository is signed with the ConfigDirector signing key. The signature is the .asc file next to each one.

  • Fingerprint: 779A DCFB 334D A3FD 2E00 5AB4 3CD4 0757 E05C 6B4C
  • User ID: ConfigDirector <opensource@configdirector.com>
  • Expires: 2028-08-20

The key is published on keys.openpgp.org and keyserver.ubuntu.com, and in full in the KEYS.md file of the Android SDK and Java SDK repositories.

Gradle dependency verification

If your build verifies signatures with Gradle's dependency verification, trust the key for the com.configdirector group by adding this entry to <trusted-keys> in gradle/verification-metadata.xml. Gradle downloads the key from the key servers above.

<trusted-key id="779ADCFB334DA3FD2E005AB43CD40757E05C6B4C" group="com.configdirector"/>

gpg

Download a file and its signature, and check one against the other:

gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 779ADCFB334DA3FD2E005AB43CD40757E05C6B4C
curl -O https://maven.configdirector.com/com/configdirector/server-sdk/1.8.0/server-sdk-1.8.0.jar
curl -O https://maven.configdirector.com/com/configdirector/server-sdk/1.8.0/server-sdk-1.8.0.jar.asc
gpg --verify server-sdk-1.8.0.jar.asc server-sdk-1.8.0.jar

Check that gpg reports a good signature and shows the fingerprint above.

GitHub artifact attestations

Every jar, AAR and POM also has a GitHub artifact attestation, which records the SDK's source repository on GitHub and the release workflow run that built the file. Check a downloaded file with the GitHub CLI:

gh attestation verify server-sdk-1.8.0.jar --owner ConfigDirector

The command succeeds only when the file was built by a workflow in a ConfigDirector repository on GitHub.