Skip to content
CAI
Software that uses CAICheck a score

Triple-T/gradle-play-publisher

52.4

Weak · 25 September 2026

5.2k

lines of production code

Kotlin

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Gradle plugin designed to automate the publishing of Android applications to the Google Play Store. It handles the complete lifecycle of app distribution, including uploading APKs and bundles, managing release tracks and rollouts, and updating store listings, products, and subscriptions. The tool integrates directly into the Gradle build process, supporting modern configuration caching and various authentication methods to streamline the release workflow.

How it got here

2014–2018 — Gradle Kotlin DSL migration

6 changes.

The project underwent a comprehensive build system overhaul, migrating from a legacy Groovy implementation to the Gradle Kotlin DSL with centralized dependency management. This period involved initializing the repository structure, removing obsolete plugin code, and standardizing Maven publication configurations for consistent artifact deployment.

2019 — Gradle configuration cache and architecture rewrite

16 changes.

The plugin underwent a significant architectural rewrite to ensure compatibility with Gradle's configuration cache and isolated projects, replacing eager configuration with lazy evaluation and worker-based task execution. This period also introduced a new public configuration extension, enhanced authentication methods including service account impersonation, and added comprehensive integration tests to validate the refactored publishing workflows.

Features

Add built-in test app for manual plugin testing

A new test application has been added to the repository to facilitate manual testing of the plugin. This includes the necessary Gradle wrapper scripts (gradlew, gradlew.bat) to ensure consistent builds, a Google Play service account configuration file (google-play-auto-publisher.json) for publishing workflows, and a keystore properties file (keystore.properties) containing signing credentials required for the test app's build process.

testapp · high confidence

Add new project logo and license asset

The assets directory now includes a new SVG logo file and an HTML file displaying the Creative Commons Attribution 4.0 International License badge. This provides the visual identity asset and the required licensing attribution for the project.

assets · high confidence

New Play Publisher plugin configuration extension and plugin entry point

The plugin now exposes a new \PlayPublisherExtension\ class for configuring Google Play Publisher settings, including properties for authentication (service account credentials, application default credentials, service account impersonation), publishing behavior (default packaging method, commit behavior, track selection, promotion settings, rollout retention, user fraction, update priority, release status, release name, resolution strategy), and artifact management (prebuilt artifact directory, retainable artifacts). The \PlayPublisherPlugin\ applies this extension to the project, sets default values, and registers global tasks for bootstrapping listings, publishing APKs and bundles, uploading internal sharing artifacts, promoting releases, and publishing listings, products, and subscriptions. It also integrates with the Android Gradle Plugin to handle variants and configure per-variant extensions.

play/plugin/src/main/kotlin/com/github/triplet/gradle/play · high confidence

New utility functions for file and string operations

This change introduces new Kotlin utility files in the common/utils module to support internal operations. Constants.kt defines the plugin's internal name and Gradle task group. Io.kt adds helper functions for file system interactions, including safe directory and file creation, renaming, reading processed text, and navigating parent directories. Strings.kt provides a capitalize function for string manipulation. These utilities support the broader plugin architecture but are specific to the common/utils location.

common/utils · high confidence

Project initialization with Gradle Play Publisher v5.0.0-SNAPSHOT

The repository has been initialized with the Gradle Play Publisher plugin, currently at version 5.0.0-SNAPSHOT. This includes a comprehensive README documenting installation, authentication via service accounts, and usage for publishing Android App Bundles and APKs. The project setup features a new .editorconfig enforcing specific code style rules, a CODE\_OF\_CONDUCT.md, a CONTRIBUTING.md guide, and an MIT LICENSE. The Gradle wrapper scripts (gradlew and gradlew.bat) have been updated to modern POSIX-compliant standards, and the .gitignore has been expanded to exclude build artifacts and local configuration files.

(repo-wide) · high confidence

Removals

Removal of legacy Groovy Play Publisher plugin implementation

The legacy Groovy-based Play Publisher plugin (PlayPublisherPlugin) and its extension class have been removed from the source code. This deletion eliminates the previous mechanism that registered the 'play' Gradle plugin via META-INF/gradle-plugins and created basic publish tasks for release variants, indicating a shift away from this specific Groovy implementation.

src/main · high confidence

Behavioural changes

Centralized Maven publication configuration for Gradle Play Publisher

The build system now uses a new centralized configuration file to define Maven publication details for the Gradle Play Publisher plugin. This change standardizes how the plugin's metadata (name, description, URL, license, developer info, and SCM details) is structured for Maven publications and configures the Sonatype repository URLs and credentials for both release and snapshot builds, ensuring consistent publishing behavior.

buildSrc · high confidence

Enforce minimum Gradle 9.1.0 and Android Gradle Plugin 9.0 requirements

The plugin now validates the build environment at runtime, requiring Gradle 9.1.0 or higher and Android Gradle Plugin 9.0 or higher. If the installed versions are too old, the build fails with a clear error message and instructions on how to upgrade. Additionally, the plugin now checks that build variants are not debuggable before allowing publication, skipping or erroring on debuggable variants to prevent accidental release of debug builds.

common/validation/src/main · high confidence

New CLI options for release promotion and internal task refactoring

The plugin now exposes new command-line options for managing Play Store releases, including --retain-existing-rollout to keep staged rollouts active during promotion, --version-code to specify which version to promote, and --update-priority to set update priority. Additionally, the internal task hierarchy has been reorganized with new base classes and lifecycle tasks to support these options and improve build service integration.

play/plugin/src/main/kotlin/com/github/triplet/gradle/play/tasks/internal · high confidence

New Google auth library with proxy support and service loader architecture

The plugin now uses the new Google auth library, enabling Application Default Credentials and service account impersonation, and adds support for proxy authentication via system properties. To support these changes and improve extensibility, the internal publisher wiring has been migrated to use Java ServiceLoader for factory instantiation, and the EditManager interface has been updated to include a retainExistingRollout option for promotions.

play/android-publisher/src/main · high confidence

New plugin architecture with configuration caching support and credential improvements

The plugin has been rewritten with a new internal architecture to improve compatibility with Gradle configuration caching and isolated projects. This includes migrating extension wiring to use Gradle Property APIs, converting the edit generator task into a build service, and implementing lazy credential validation. Users also gain support for Application Default Credentials and service account impersonation, a new \retainExistingRollout\ option to prevent halting rollouts during promotion, and the ability to specify Google Play Platform credentials via an environment variable.

plugin · high confidence

Re-architected Play Publisher tasks for improved reliability and configuration cache support

The tasks in the play plugin directory (CommitEdit, InstallInternalSharingArtifact, ProcessArtifactVersionCodes, PromoteRelease, PublishApk, PublishBundle, PublishInternalSharingApk, PublishInternalSharingBundle, PublishProducts, and PublishSubscriptions) have been rewritten to use a new worker-based architecture. This change improves compatibility with Gradle's configuration cache, fixes issues with auto-resolution version codes, and ensures that internal sharing artifacts are installed correctly via ADB. Users will experience more stable builds, better handling of release notes and track promotions, and support for uploading native debug symbols.

play/plugin/src/main/kotlin/com/github/triplet/gradle/play/tasks · high confidence

Refactor Play Publisher into modular architecture with new release management logic

The android-publisher module has been rewritten to separate the build-side configuration from API dependencies, introducing a new \PlayPublisher\ interface and \DefaultPlayPublisher\ implementation that uses ServiceLoader for factory instantiation. This change includes a new \TrackManager\ that handles release updates and promotions, adding support for the \retainExistingRollout\ option to prevent halting rollouts during promotion, and fixing crashes when tracks or subscriptions do not exist. The module also adds support for uploading native debug symbols, copying release notes from previous releases, and automatically setting the release status to \inProgress\ when a user fraction is specified but no status is provided.

android-publisher · high confidence

Refactor Play Worker base classes and parameter handling

The internal worker architecture for Play publishing tasks has been restructured. New base classes (PlayWorkerBase, EditWorkerBase, PublishArtifactWorkerBase) and a dedicated Params file now centralize configuration, API service access, and parameter copying logic. This refactoring introduces specific handling for release track names containing colons by supporting alternative file naming conventions (replacing colons with hyphens) when looking up release notes and console names, and ensures that commit actions are correctly scheduled or skipped based on configuration.

play/plugin/src/main/kotlin/com/github/triplet/gradle/play/tasks/internal/workers · high confidence

Refactor internal plugin wiring and configuration resolution

The internal plugin implementation has been restructured to improve configuration cache compatibility and task isolation. A new \ApkSpec\ class now resolves APK file paths at task-action time rather than configuration time, preventing failures when the Gradle configuration cache is enabled. Task registration and \CommitEdit\ task lookup have been centralized in \Plugins.kt\, with logic added to respect isolated project settings and ensure tasks are registered in the correct project scope. Additionally, extension merging logic has been refined to correctly prioritize configuration overrides from CLI, product flavors, dimensions, and build types, ensuring that the highest-priority extension settings are applied consistently.

play/plugin/src/main/kotlin/com/github/triplet/gradle/play/internal · high confidence

Test coverage

Add built-in test app for manual plugin testing; Added integration tests for edit and track management; Added test fixtures for mocking Play Publisher interactions; Added unit tests for runtime validation logic; Expanded integration test fixtures for Play Plugin resource generation and publishing.

Dependencies

Migrate build system to Gradle Kotlin DSL and modern dependency management

The project's build configuration has been completely rewritten from Groovy to the Gradle Kotlin DSL, introducing a modular structure with separate build scripts for the main plugin, common utilities, validation, and the Android publisher library. Dependency management is now centralized in version catalogs (defined in settings.gradle.kts), explicitly specifying versions for the Android Gradle Plugin (9.0.0), Google API clients, and JUnit 5. The build now uses the modern Gradle Plugin Portal publishing plugin and the Gradle Nexus Publish Plugin for artifact deployment, replacing the legacy Groovy-based Nexus plugin. Additionally, the test infrastructure has been updated to use JUnit Platform, and the build enforces stricter validation and parallel test execution.

(dependencies) · high confidence

Upgrade Gradle wrapper to version 9.3.0

The Gradle wrapper configuration in the testapp has been updated to use Gradle 9.3.0. This change ensures that builds are executed with the specified version of the Gradle build tool, providing consistency across development environments and leveraging any improvements or fixes included in this release.

gradle, testapp/gradle · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 39 → 52 (+13.2)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 97 (-2.0)
  • Architecture 94 → 98 (+4.2)
  • Maturity 47 → 60 (+13.4)
  • Readiness 27 → 32 (+4.6)
  • Security 30 → 67 (+37.5)

Resolved (25)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low: security finding (details withheld)
  • Low: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No artifact signing
  • No exposed public API
  • No tests found
  • …and 5 more

New (40)

  • Change coupling: PlayPublisherPlugin.kt ↔ Plugins.kt (play/plugin/src/main/kotlin/com/github/triplet/gradle/play/PlayPublisherPlugin.kt)
  • ClassTooLong: PlayPublisherPlugin (play/plugin/src/main/kotlin/com/github/triplet/gradle/play/PlayPublisherPlugin.kt)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (20 lines × 2) (play/plugin/src/main/kotlin/com/github/triplet/gradle/play/tasks/PublishApk.kt)
  • FileTooLong: play/PlayPublisherPlugin.kt (play/plugin/src/main/kotlin/com/github/triplet/gradle/play/PlayPublisherPlugin.kt)
  • High secret: WD-SECRET-0004 (testapp/keystore.jks)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 20 more

Changes since last survey

  • 5 commits — 3 feature/other, 2 fixes

By area

  • (root) — 3 commits
  • play/plugin — 2 commits

Notable commits

  • fix: Fix Isolated Projects error in Gradle 9.7 (#1194)
  • fix: Fix failing bootstrapListing task (#1195)
  • change: Install androidx.lint-gradle plugin to flag common Gradle problems (#1196)
  • change: v4.1.0
  • change: v4.1.1

Architecture

  • Containers 0 added · 0 removed · contexts 2 added · 0 removed · edges 1 added · 0 removed

Added bounded contexts (2)

  • android-publisher
  • plugin

Added dependency edges (1)

  • plugin → android-publisher

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Triple-T/gradle-play-publisher was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c7dfb4fd8a9043be9146d1d8062a048e1e3d80ec — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-dd72cc24c749.