Maven Repository
The ConfigDirector Android and Java SDKs, and the OpenFeature providers built on them, are published to the ConfigDirector Maven repository:
https://maven.configdirector.com
Anyone can download from it, without an account or credentials. Once a version is published there it never changes: its files are never replaced or deleted.
Artifacts
| Artifact | Contents |
|---|---|
com.configdirector:android-sdk | The Android SDK |
com.configdirector:android-sdk-compose | Jetpack Compose bindings for the Android SDK |
com.configdirector:android-sdk-testing | Tools for testing code that uses the Android SDK |
com.configdirector:openfeature-android-provider | The OpenFeature Android provider |
com.configdirector:server-sdk | The Java server SDK |
com.configdirector:server-sdk-testing | Tools for testing code that uses the Java server SDK |
com.configdirector:openfeature-server-provider | The OpenFeature Java provider |
Older versions on Maven Central
Versions up to Android SDK 1.6.0, OpenFeature Android provider 1.2.0, Java server SDK 1.7.0 and OpenFeature Java provider 1.4.0 were published to Maven Central under older names. Newer versions are only in this repository.
| Name on Maven Central | Name in this repository |
|---|---|
configdirector-android | android-sdk |
configdirector-android-compose | android-sdk-compose |
configdirector-android-testing | android-sdk-testing |
configdirector-openfeature-android-provider | openfeature-android-provider |
configdirector-server-sdk | server-sdk |
configdirector-server-sdk-testing | server-sdk-testing |
configdirector-openfeature-server-provider | openfeature-server-provider |
To upgrade from a version on Maven Central, add the repository to your build and change the artifact names. Change all of them at once: an artifact under its old name and the same artifact under its new name contain the same classes, so they cannot be on the same classpath.
Add the repository to your build
Gradle
If your build declares its repositories in settings.gradle.kts or settings.gradle, under dependencyResolutionManagement, add the repository there. Android Studio sets up new projects this way, and their builds fail if a module's build file declares a repository.
dependencyResolutionManagement {
repositories {
google()
mavenCentral()
exclusiveContent {
forRepository {
maven {
name = "ConfigDirector"
url = uri("https://maven.configdirector.com")
}
}
filter {
includeGroup("com.configdirector")
}
}
}
}
dependencyResolutionManagement {
repositories {
google()
mavenCentral()
exclusiveContent {
forRepository {
maven {
name = 'ConfigDirector'
url = 'https://maven.configdirector.com'
}
}
filter {
includeGroup 'com.configdirector'
}
}
}
}
Otherwise, add it to the repositories block of your build file:
repositories {
mavenCentral()
exclusiveContent {
forRepository {
maven {
name = "ConfigDirector"
url = uri("https://maven.configdirector.com")
}
}
filter {
includeGroup("com.configdirector")
}
}
}
repositories {
mavenCentral()
exclusiveContent {
forRepository {
maven {
name = 'ConfigDirector'
url = 'https://maven.configdirector.com'
}
}
filter {
includeGroup 'com.configdirector'
}
}
}
With exclusiveContent, Gradle looks for ConfigDirector artifacts only in this repository, and looks for nothing else there. Keep the other repositories your build already lists.
Maven
Add the repository to pom.xml:
<repositories>
<repository>
<id>configdirector</id>
<url>https://maven.configdirector.com</url>
<releases><enabled>true</enabled></releases>
<snapshots><enabled>false</enabled></snapshots>
</repository>
</repositories>
Dependabot
Dependabot can't reach this repository until .github/dependabot.yml declares it, even though the repository needs no credentials. Declare it so that Dependabot can open pull requests for new versions of the SDKs:
version: 2
registries:
configdirector:
type: maven-repository
url: https://maven.configdirector.com
updates:
- package-ecosystem: "gradle"
directory: "/"
registries:
- configdirector
schedule:
interval: "weekly"
For a Maven build, the package-ecosystem is "maven". If the file already has updates entries, add configdirector to the registries of each entry that covers a build using the SDKs.
Company repository managers
If your builds download their dependencies through a repository manager such as Sonatype Nexus Repository or JFrog Artifactory, rather than from public repositories directly, its administrator adds this repository once:
- Create a Maven proxy repository (a remote repository in Artifactory) with
https://maven.configdirector.comas its URL. It only serves release versions and needs no credentials. - Limit it to the
com.configdirectorgroup: in Nexus with a routing rule that allows^/com/configdirector/.*, in Artifactory with the include patterncom/configdirector/**. - Add it to the group repository (the virtual repository in Artifactory) that your builds use.
Your builds keep listing only the repository manager, and get the SDKs through it like any other dependency.
Verify what you download
Every jar, AAR and POM in the repository is signed with the ConfigDirector signing key. The signature is the .asc file next to each one.
- Fingerprint:
779A DCFB 334D A3FD 2E00 5AB4 3CD4 0757 E05C 6B4C - User ID:
ConfigDirector <opensource@configdirector.com> - Expires: 2028-08-20
The key is published on keys.openpgp.org and keyserver.ubuntu.com, and in full in the KEYS.md file of the Android SDK and Java SDK repositories.
Gradle dependency verification
If your build verifies signatures with Gradle's dependency verification, trust the key for the com.configdirector group by adding this entry to <trusted-keys> in gradle/verification-metadata.xml. Gradle downloads the key from the key servers above.
<trusted-key id="779ADCFB334DA3FD2E005AB43CD40757E05C6B4C" group="com.configdirector"/>
gpg
Download a file and its signature, and check one against the other:
gpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 779ADCFB334DA3FD2E005AB43CD40757E05C6B4C
curl -O https://maven.configdirector.com/com/configdirector/server-sdk/1.8.0/server-sdk-1.8.0.jar
curl -O https://maven.configdirector.com/com/configdirector/server-sdk/1.8.0/server-sdk-1.8.0.jar.asc
gpg --verify server-sdk-1.8.0.jar.asc server-sdk-1.8.0.jar
Check that gpg reports a good signature and shows the fingerprint above.
GitHub artifact attestations
Every jar, AAR and POM also has a GitHub artifact attestation, which records the SDK's source repository on GitHub and the release workflow run that built the file. Check a downloaded file with the GitHub CLI:
gh attestation verify server-sdk-1.8.0.jar --owner ConfigDirector
The command succeeds only when the file was built by a workflow in a ConfigDirector repository on GitHub.