who_need_help/docs/google-play-release-candidate-2026-08-03.md

83 lines
3.6 KiB
Markdown

# Google Play release candidate — 2026-08-03
This document identifies the exact locally validated artifact intended for the
first Google Play upload. It contains no credentials or private signing-key
material.
## Upload artifact
- File: `android/dist-release-20260803-current/who-need-help-release.aab`
- SHA-256: `14d0ad2d680edcb94a1434ed302e14a0ebe65873fbec5a5bddeff384c13e91e1`
- Package: `org.whoneedhelp.mobile`
- Version code: `1`
- Version name: `0.1.0`
- Minimum SDK: `24`
- Target SDK: `37`
- Source fingerprint:
`8e8a5c9d2d6dcf64bc105a90cdf0b6ed3cfa36b08a354cafdf159f67ea21e00d`
The source fingerprint stored next to the artifact matched a fresh local
fingerprint after the build.
## Upload certificate
- SHA-256:
`A5:74:2B:AE:70:C6:D0:34:E3:75:44:B6:2E:37:A3:75:C0:E0:05:64:74:50:F4:0F:29:B2:A9:84:F9:FD:B8:FB`
- SHA-1:
`8C:84:D5:CA:2F:B7:EA:2B:7E:08:2D:D1:CD:E8:AC:60:56:AA:1B:3C`
This upload certificate is not the Google Play App Signing certificate. After
the first upload, record the Play-generated certificate separately and add its
fingerprints to production Google/Firebase configuration and the production
App Links association.
## Validation evidence
- `bundletool` validation passed.
- Release unit tests and Android lint passed; the lint report contains no
errors or warnings.
- R8 release build completed successfully.
- APK and AAB signing verification passed.
- Universal APK generated from this AAB:
`android/dist-release-20260803-current/who-need-help-release-universal.apk`
- Universal APK SHA-256:
`2d34eb24ad06bd0022ef5f711ffc5fa2c7325b5d092a521cc7f0f8cf093332eb`
- The release APK SHA-256 is
`73ff3579dd22197e20ab5882b4a98f858a9d59a6622bf80d3ddde48ae03bf931`.
- The release APK was installed over the existing production package on the
authorised physical Android 16 / API 36 device without deleting app data.
- A cold start completed in 614 ms and the production origin rendered on the
device.
- `https://whoneedhelp.com/safety` was delivered to
`org.whoneedhelp.mobile/.MainActivity` and rendered in the installed app.
- No application crash or TLS/SSL/WebView load failure was present in the
filtered release smoke-test log.
- The complete repository quality run passed 443 ExUnit tests and 14 browser
dependency tests, plus compiler, format, xref, Credo, Sobelow, Dialyzer,
dependency audit, container, Compose, Helm, migration, rollback,
observability, and image-security gates.
- The final runtime image scan reported zero detected vulnerabilities.
## First Play Console session
1. Create **Who Need Help** as an app (not a game), free, default language
English (United States), support email `contact@whoneedhelp.com`.
2. Accept the policy, export-law, and Play App Signing declarations.
3. Complete the prepared store listing and App content sections using
`android/play-store/` and `android/store-assets/`.
4. Upload only the AAB identified above to an internal-testing release first.
5. Install the Play-delivered build from the internal-test opt-in link and
repeat the production-origin, sign-in, notification, location, and App Link
smoke tests.
6. Record the Play App Signing SHA-1 and SHA-256 before starting the closed
test.
7. Start a closed test with at least 12 continuously opted-in testers for at
least 14 days before requesting production access.
Official references:
- https://support.google.com/googleplay/android-developer/answer/9859152
- https://support.google.com/googleplay/android-developer/answer/9842756
- https://support.google.com/googleplay/android-developer/answer/9845334
- https://support.google.com/googleplay/android-developer/answer/14151465