# Google Play release candidate — 2026-08-01 This document identifies the exact locally validated artifact intended for the first Google Play upload. It contains no credentials or private signing-key material. ## Upload artifact - File: `android/dist-release-20260801-final/who-need-help-release.aab` - SHA-256: `55f05f4b7394be40f2740529eb8597279f9af25269b97c4f58fa4446b431bb14` - Package: `org.whoneedhelp.mobile` - Version code: `1` - Version name: `0.1.0` - Minimum SDK: `24` - Target SDK: `37` - Source fingerprint: `8339812414061c6090b91f0abfe3562633926b4e72159885f57e7bd4000d2555` The source fingerprint stored next to the artifact matched a fresh local fingerprint after the build. ## Upload certificate - SHA-256: `A5:74:2B:AE:70:C6:D0:34:E3:75:44:B6:2E:37:A3:75:C0:E0:05:64:74:50:F4:0F:29:B2:A9:84:F9:FD:B8:FB` - SHA-1: `8C:84:D5:CA:2F:B7:EA:2B:7E:08:2D:D1:CD:E8:AC:60:56:AA:1B:3C` This upload certificate is not the Google Play App Signing certificate. After the first upload, record the Play-generated certificate separately and add its fingerprints to production Google/Firebase configuration and the production App Links association. ## Validation evidence - `bundletool` validation passed. - Release unit tests and Android lint passed. - R8 release build completed successfully. - APK and AAB signing verification passed. - Universal APK generated from this AAB: `android/dist-release-20260801-final/who-need-help-release-universal.apk` - Universal APK SHA-256: `cf8bf8001b02447fb63ee73b3d8dd980485c38113cc7e0f67705690afa64f79c` - The universal APK was installed on the authorised physical Android 16 / API 36 device and cold-started successfully. - The production origin rendered correctly on the device. - `https://whoneedhelp.com/safety` opened in the installed production app. - No application crash or TLS/SSL/WebView load failure was observed in the release smoke-test log. - The complete repository quality run passed 414 tests plus compiler, format, xref, Credo, Sobelow, Dialyzer, dependency audit, container, Compose, Helm, migration, rollback, observability, and image-security gates. ## First Play Console session 1. Create **Who Need Help** as an app (not a game), free, default language English (United States), support email `contact@whoneedhelp.com`. 2. Accept the policy, export-law, and Play App Signing declarations. 3. Complete the prepared store listing and App content sections using `android/play-store/` and `android/store-assets/`. 4. Upload only the AAB identified above to an internal-testing release first. 5. Install the Play-delivered build from the internal-test opt-in link and repeat the production-origin, sign-in, notification, location, and App Link smoke tests. 6. Record the Play App Signing SHA-1 and SHA-256 before starting the closed test. 7. Start a closed test with at least 12 continuously opted-in testers for at least 14 days before requesting production access. Official references: - https://support.google.com/googleplay/android-developer/answer/9859152 - https://support.google.com/googleplay/android-developer/answer/9842756 - https://support.google.com/googleplay/android-developer/answer/9845334 - https://support.google.com/googleplay/android-developer/answer/14151465