who_need_help/docs/google-play-release-candidate-2026-08-01.md

3.2 KiB

Google Play release candidate — 2026-08-01

This document identifies the exact locally validated artifact intended for the first Google Play upload. It contains no credentials or private signing-key material.

Upload artifact

  • File: android/dist-release-20260801-final/who-need-help-release.aab
  • SHA-256: 55f05f4b7394be40f2740529eb8597279f9af25269b97c4f58fa4446b431bb14
  • Package: org.whoneedhelp.mobile
  • Version code: 1
  • Version name: 0.1.0
  • Minimum SDK: 24
  • Target SDK: 37
  • Source fingerprint: 8339812414061c6090b91f0abfe3562633926b4e72159885f57e7bd4000d2555

The source fingerprint stored next to the artifact matched a fresh local fingerprint after the build.

Upload certificate

  • SHA-256: A5:74:2B:AE:70:C6:D0:34:E3:75:44:B6:2E:37:A3:75:C0:E0:05:64:74:50:F4:0F:29:B2:A9:84:F9:FD:B8:FB
  • SHA-1: 8C:84:D5:CA:2F:B7:EA:2B:7E:08:2D:D1:CD:E8:AC:60:56:AA:1B:3C

This upload certificate is not the Google Play App Signing certificate. After the first upload, record the Play-generated certificate separately and add its fingerprints to production Google/Firebase configuration and the production App Links association.

Validation evidence

  • bundletool validation passed.
  • Release unit tests and Android lint passed.
  • R8 release build completed successfully.
  • APK and AAB signing verification passed.
  • Universal APK generated from this AAB: android/dist-release-20260801-final/who-need-help-release-universal.apk
  • Universal APK SHA-256: cf8bf8001b02447fb63ee73b3d8dd980485c38113cc7e0f67705690afa64f79c
  • The universal APK was installed on the authorised physical Android 16 / API 36 device and cold-started successfully.
  • The production origin rendered correctly on the device.
  • https://whoneedhelp.com/safety opened in the installed production app.
  • No application crash or TLS/SSL/WebView load failure was observed in the release smoke-test log.
  • The complete repository quality run passed 414 tests plus compiler, format, xref, Credo, Sobelow, Dialyzer, dependency audit, container, Compose, Helm, migration, rollback, observability, and image-security gates.

First Play Console session

  1. Create Who Need Help as an app (not a game), free, default language English (United States), support email contact@whoneedhelp.com.
  2. Accept the policy, export-law, and Play App Signing declarations.
  3. Complete the prepared store listing and App content sections using android/play-store/ and android/store-assets/.
  4. Upload only the AAB identified above to an internal-testing release first.
  5. Install the Play-delivered build from the internal-test opt-in link and repeat the production-origin, sign-in, notification, location, and App Link smoke tests.
  6. Record the Play App Signing SHA-1 and SHA-256 before starting the closed test.
  7. Start a closed test with at least 12 continuously opted-in testers for at least 14 days before requesting production access.

Official references: