98 lines
4.6 KiB
Markdown
98 lines
4.6 KiB
Markdown
# Google Play release candidate — 2026-08-03
|
|
|
|
This document identifies the exact locally validated artifact intended for the
|
|
first Google Play upload. It contains no credentials or private signing-key
|
|
material.
|
|
|
|
## Upload artifact
|
|
|
|
- File: `android/dist-release-20260803-162910/who-need-help-release.aab`
|
|
- SHA-256: `03d39a9a08e9ca7569caccf1c7bd75e9349f7655935e7bbf23d1998cd37b3837`
|
|
- Package: `org.whoneedhelp.mobile`
|
|
- Version code: `1`
|
|
- Version name: `0.1.0`
|
|
- Minimum SDK: `24`
|
|
- Target SDK: `37`
|
|
- Source fingerprint:
|
|
`34de017cb2a08dcc19fe0b531fb2473df30de3f559cdbac914881059299e0992`
|
|
|
|
The source fingerprint stored next to the artifact matched a fresh local
|
|
fingerprint after the build.
|
|
|
|
## Upload certificate
|
|
|
|
- SHA-256:
|
|
`A5:74:2B:AE:70:C6:D0:34:E3:75:44:B6:2E:37:A3:75:C0:E0:05:64:74:50:F4:0F:29:B2:A9:84:F9:FD:B8:FB`
|
|
- SHA-1:
|
|
`8C:84:D5:CA:2F:B7:EA:2B:7E:08:2D:D1:CD:E8:AC:60:56:AA:1B:3C`
|
|
|
|
This upload certificate is not the Google Play App Signing certificate. After
|
|
the first upload, record the Play-generated certificate separately and add its
|
|
fingerprints to production Google/Firebase configuration and the production
|
|
App Links association.
|
|
|
|
## Validation evidence
|
|
|
|
- `bundletool` validation passed.
|
|
- Release unit tests and Android lint passed; the lint report contains no
|
|
errors or warnings.
|
|
- R8 release build completed successfully.
|
|
- APK and AAB signing verification passed.
|
|
- The native disclosure shown immediately before Android location permission
|
|
explains collection and transmission of precise location, background use
|
|
while the app is minimized or not in use, the persistent notification, the
|
|
Stop action, raw-location deletion, and retained summary safety evidence.
|
|
- Universal APK generated from this AAB:
|
|
`android/dist-release-20260803-162910/who-need-help-release-universal.apk`
|
|
- Universal APK SHA-256:
|
|
`d079a42809155faa86da72281c985f01d4134097e4410cdfbf244869b3027d21`
|
|
- The bundletool archive SHA-256 is
|
|
`9e9d034c44e55c22bc6d6e7ac3b294e5339ee808170fe0f6c80b1307f9de5907`.
|
|
- The release APK SHA-256 is
|
|
`e40f72558aa8b0c94ad917ff885618ba56199acf5dd2beb2f331305f0748f5d2`.
|
|
- The release APK was installed over the existing production package on the
|
|
authorised physical Android 16 / API 36 device without deleting app data.
|
|
- Physical-device evidence is stored in
|
|
`output/android-physical-release/20260803-1934-policy/` and
|
|
`output/android-physical-release/20260803-1934-policy-clean/`. The production
|
|
home and Safety pages rendered without visible cropping or overlap.
|
|
- `https://whoneedhelp.com/safety` was delivered to
|
|
`org.whoneedhelp.mobile/.MainActivity` by an implicit Android App Link intent
|
|
and rendered in the installed app. Android reported the domain as verified,
|
|
delivered the intent to `org.whoneedhelp.mobile/.MainActivity`, and completed
|
|
the clean cold App Link launch in 654 ms.
|
|
- A PID-scoped log captured after the clean launch contained no application
|
|
crash, AndroidRuntime, TLS/SSL, or WebView load error. An earlier diagnostic
|
|
run crashed Android's separate `UiAutomation` process; the application
|
|
remained running and that tool crash is not counted as app evidence.
|
|
- The complete repository quality run passed 443 ExUnit tests and 14 browser
|
|
dependency tests, plus compiler, format, xref, Credo, Sobelow, Dialyzer,
|
|
dependency audit, container, Compose, Helm, migration, rollback,
|
|
observability, and image-security gates.
|
|
- The final runtime image scan reported zero detected vulnerabilities.
|
|
|
|
## First Play Console session
|
|
|
|
1. Create **Who Need Help** as an app (not a game), free, default language
|
|
English (United States), support email `contact@whoneedhelp.com`.
|
|
2. Accept the policy, export-law, and Play App Signing declarations.
|
|
3. Complete the prepared store listing and App content sections using
|
|
`android/play-store/` and `android/store-assets/`.
|
|
4. Upload only the AAB identified above to an internal-testing release first.
|
|
The older `android/dist-release-20260803-183258/` candidate is superseded and
|
|
must not be uploaded.
|
|
5. Install the Play-delivered build from the internal-test opt-in link and
|
|
repeat the production-origin, sign-in, notification, location, and App Link
|
|
smoke tests.
|
|
6. Record the Play App Signing SHA-1 and SHA-256 before starting the closed
|
|
test.
|
|
7. Start a closed test with at least 12 continuously opted-in testers for at
|
|
least 14 days before requesting production access.
|
|
|
|
Official references:
|
|
|
|
- https://support.google.com/googleplay/android-developer/answer/9859152
|
|
- https://support.google.com/googleplay/android-developer/answer/9842756
|
|
- https://support.google.com/googleplay/android-developer/answer/9845334
|
|
- https://support.google.com/googleplay/android-developer/answer/14151465
|