You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Android previously compiled the protocol from local source while its published POM pointed consumers at a separate Maven artifact. That allowed Kit to ship references to classes missing from its declared dependency.
The SDK and Android sample now compile against the pinned Maven Central protocol artifact in normal builds, CI, and releases. Joint development opts into source with dev android local <command> or -PuseLocalProtocol=true. Remote Kit publication rejects local mode, while React Native's explicit --local flow can still publish both artifacts to Maven Local.
The protocol release version and Kit's dependency pin are separate so a protocol release PR can merge before Kit adopts the new artifact. Protocol tests and lint run independently, and Kit publication runs unit tests and API checks before uploading.
A small :lib:verifyPublishedProtocol task also requires release and unit-test classpaths to resolve the declared ECP module at exactly the catalog-pinned version. It catches project substitution and version drift introduced by dependency resolution, runs automatically with SDK unit tests and remote publication, and skips explicit local mode. This retains the useful safeguard from #832 without adding a fixture framework or another build-mode toggle.
Release process
For a feature spanning all three packages, the order is ECP → Android Kit → React Native:
Release ECP to Maven Central. Bump embeddedCheckoutProtocolAndroid with the protocol changes and API baseline. Keep Kit's embeddedCheckoutProtocolAndroidDependency at the existing published version while this PR passes CI, merges, and releases.
Adopt ECP and release Android Kit. Once the protocol artifact and metadata are available, update Kit's ECP dependency pin, make the SDK changes, and bump checkoutKitAndroid. Run normal SDK/sample CI and API checks against that published ECP version, then merge and publish Kit to Maven Central.
Adopt Android Kit and release RN. Once Kit is available, update checkoutKit.nativeSdkVersions.android and the RN package's own version. Run normal RN Android tests and the sample build against the published Kit and its transitive ECP dependency, plus the other required RN checks. Merge and publish RN to npm. RN does not need its own ECP pin.
At each stage, use the Release package workflow's dry run and draft release flow. Wait for actual registry availability before verifying the next package; a GitHub release/tag alone is insufficient. The workflows do not automatically sequence the stages. The RN npm publish job builds/packs JavaScript and does not rerun Android compilation, so RN Android CI must pass before release.
Only changed dependencies need new releases: Android-only changes can keep the ECP pin, and RN-only changes can keep both native pins. Update RN's iOS pin only when needed, after its required Swift release is available on CocoaPods. Package versions remain independent.
This waterfall makes each package a consumer of the published dependency it declares. It catches missing API during compilation, gives each layer an explicit version boundary, and preserves ECP as a shared transitive dependency rather than embedding duplicate protocol classes. The cost is upstream publication time and a downstream CI run at each adoption. Local overrides support development across stacked branches, but normal CI must pass against published artifacts before those downstream PRs merge.
Published dependency: 504 SDK tests, 99 sample tests, SDK API check, release AAR, and sample debug build passed.
Protocol source: 50 tests passed through dev protocol test kotlin.
Local override: dev android local api check passed for Kit and protocol.
SDK and sample detekt tasks passed.
Publication guard: an attempted local-mode publication to an isolated file repository was rejected before uploading any artifacts.
Resolved-dependency guard: temporary Gradle init scripts against the real Android project confirmed rejection of forced version drift on all four release/unit-test classpaths and of project substitution. Tests also exercised the guard through the actual unit-test and publication tasks.
Local-mode compatibility: verification skipped as expected, remote publication remained blocked, and Kit plus ECP still published successfully to an isolated Maven Local repository.
React Native local publishing produced both artifacts in a temporary Maven Local repository with the expected protocol dependency.
Release-version regression test passed: protocol publication can advance while Kit still references its older dependency.
Measured from the PR base SHA and PR head SHA. The file breakdown shows uncompressed sizes within each package artifact, so individual files do not sum to the compressed artifact total. This comment reports package artifact sizes only; it is not a final app binary-size report.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes are you making?
Android previously compiled the protocol from local source while its published POM pointed consumers at a separate Maven artifact. That allowed Kit to ship references to classes missing from its declared dependency.
The SDK and Android sample now compile against the pinned Maven Central protocol artifact in normal builds, CI, and releases. Joint development opts into source with
dev android local <command>or-PuseLocalProtocol=true. Remote Kit publication rejects local mode, while React Native's explicit--localflow can still publish both artifacts to Maven Local.The protocol release version and Kit's dependency pin are separate so a protocol release PR can merge before Kit adopts the new artifact. Protocol tests and lint run independently, and Kit publication runs unit tests and API checks before uploading.
A small
:lib:verifyPublishedProtocoltask also requires release and unit-test classpaths to resolve the declared ECP module at exactly the catalog-pinned version. It catches project substitution and version drift introduced by dependency resolution, runs automatically with SDK unit tests and remote publication, and skips explicit local mode. This retains the useful safeguard from #832 without adding a fixture framework or another build-mode toggle.Release process
For a feature spanning all three packages, the order is ECP → Android Kit → React Native:
embeddedCheckoutProtocolAndroidwith the protocol changes and API baseline. Keep Kit'sembeddedCheckoutProtocolAndroidDependencyat the existing published version while this PR passes CI, merges, and releases.checkoutKitAndroid. Run normal SDK/sample CI and API checks against that published ECP version, then merge and publish Kit to Maven Central.checkoutKit.nativeSdkVersions.androidand the RN package's ownversion. Run normal RN Android tests and the sample build against the published Kit and its transitive ECP dependency, plus the other required RN checks. Merge and publish RN to npm. RN does not need its own ECP pin.At each stage, use the Release package workflow's dry run and draft release flow. Wait for actual registry availability before verifying the next package; a GitHub release/tag alone is insufficient. The workflows do not automatically sequence the stages. The RN npm publish job builds/packs JavaScript and does not rerun Android compilation, so RN Android CI must pass before release.
Only changed dependencies need new releases: Android-only changes can keep the ECP pin, and RN-only changes can keep both native pins. Update RN's iOS pin only when needed, after its required Swift release is available on CocoaPods. Package versions remain independent.
This waterfall makes each package a consumer of the published dependency it declares. It catches missing API during compilation, gives each layer an explicit version boundary, and preserves ECP as a shared transitive dependency rather than embedding duplicate protocol classes. The cost is upstream publication time and a downstream CI run at each adoption. Local overrides support development across stacked branches, but normal CI must pass against published artifacts before those downstream PRs merge.
The coordinated release guide, RN release guide, Android README, and PR release checklists now document this process.
How to test
Verified locally:
dev protocol test kotlin.dev android local api checkpassed for Kit and protocol.detekttasks passed.git diff --checkpassed.Before you merge