who_need_help/docs/google-play-release-candidate-2026-08-03.md

5.2 KiB

Google Play release candidate — 2026-08-03

This document identifies the exact locally validated artifact intended for the first Google Play upload. It contains no credentials or private signing-key material.

Upload artifact

  • File: android/dist-release-20260803-162910/who-need-help-release.aab
  • SHA-256: 03d39a9a08e9ca7569caccf1c7bd75e9349f7655935e7bbf23d1998cd37b3837
  • Package: org.whoneedhelp.mobile
  • Version code: 1
  • Version name: 0.1.0
  • Minimum SDK: 24
  • Target SDK: 37
  • Source fingerprint: f2f281210d11465d8f7fda20a78d1ed2527660d2e8a10a29ed31bf031a29ce43

The source fingerprint stored next to the artifact matched a fresh local fingerprint after the build.

Upload certificate

  • SHA-256: A5:74:2B:AE:70:C6:D0:34:E3:75:44:B6:2E:37:A3:75:C0:E0:05:64:74:50:F4:0F:29:B2:A9:84:F9:FD:B8:FB
  • SHA-1: 8C:84:D5:CA:2F:B7:EA:2B:7E:08:2D:D1:CD:E8:AC:60:56:AA:1B:3C

This upload certificate is not a Google Play App Signing certificate. After the first upload, record every Play-generated signing certificate separately and add every applicable fingerprint to production Google/Firebase configuration and the production App Links association. Current Play signing can expose multiple identities for quantum-ready hybrid signing, so the live Console is authoritative; do not assume that there will be only one Play SHA-256 fingerprint.

Validation evidence

  • bundletool validation passed.
  • Release unit tests and Android lint passed; the lint report contains no errors or warnings.
  • R8 release build completed successfully.
  • APK and AAB signing verification passed.
  • The native disclosure shown immediately before Android location permission explains collection and transmission of precise location, background use while the app is minimized or not in use, the persistent notification, the Stop action, raw-location deletion, and retained summary safety evidence.
  • Universal APK generated from this AAB: android/dist-release-20260803-162910/who-need-help-release-universal.apk
  • Universal APK SHA-256: d079a42809155faa86da72281c985f01d4134097e4410cdfbf244869b3027d21
  • The bundletool archive SHA-256 is 9e9d034c44e55c22bc6d6e7ac3b294e5339ee808170fe0f6c80b1307f9de5907.
  • The release APK SHA-256 is e40f72558aa8b0c94ad917ff885618ba56199acf5dd2beb2f331305f0748f5d2.
  • The release APK was installed over the existing production package on the authorised physical Android 16 / API 36 device without deleting app data.
  • Physical-device evidence is stored in output/android-physical-release/20260803-1934-policy/ and output/android-physical-release/20260803-1934-policy-clean/. The production home and Safety pages rendered without visible cropping or overlap.
  • https://whoneedhelp.com/safety was delivered to org.whoneedhelp.mobile/.MainActivity by an implicit Android App Link intent and rendered in the installed app. Android reported the domain as verified, delivered the intent to org.whoneedhelp.mobile/.MainActivity, and completed the clean cold App Link launch in 654 ms.
  • A PID-scoped log captured after the clean launch contained no application crash, AndroidRuntime, TLS/SSL, or WebView load error. An earlier diagnostic run crashed Android's separate UiAutomation process; the application remained running and that tool crash is not counted as app evidence.
  • The complete repository quality run passed 443 ExUnit tests and 14 browser dependency tests, plus compiler, format, xref, Credo, Sobelow, Dialyzer, dependency audit, container, Compose, Helm, migration, rollback, observability, and image-security gates.
  • The final runtime image scan reported zero detected vulnerabilities.

Current Play Console state

The verified personal developer account contains the Who Need Help application with Play application ID 4972430103169452589. Play App Signing was accepted. The internal-testing draft contains the exact version-code 1 AAB identified above, but the release has not yet been saved/published to testers. A failed duplicate-upload row must not be confused with the accepted artifact.

The remaining Console sequence is:

  1. Keep the accepted version-code 1 artifact and remove only the failed duplicate-upload row from the draft.
  2. Save/publish the internal release and obtain every Play App Signing SHA-1 and SHA-256 shown under Test and release → Setup → App signing.
  3. Complete the prepared store listing and App content sections using android/play-store/ and android/store-assets/, including the mandatory location foreground-service declaration and demonstration video described in android/play-store/location-and-fgs-declaration.md.
  4. Install the Play-delivered build from the internal-test opt-in link and repeat the production-origin, sign-in, notification, location, and App Link smoke tests.
  5. Start a closed test with at least 12 continuously opted-in testers for at least 14 days before requesting production access.

Official references: