who_need_help/docs/google-play-release-candidate-2026-08-01.md

76 lines
3.2 KiB
Markdown

# Google Play release candidate — 2026-08-01
This document identifies the exact locally validated artifact intended for the
first Google Play upload. It contains no credentials or private signing-key
material.
## Upload artifact
- File: `android/dist-release-20260801-final/who-need-help-release.aab`
- SHA-256: `55f05f4b7394be40f2740529eb8597279f9af25269b97c4f58fa4446b431bb14`
- Package: `org.whoneedhelp.mobile`
- Version code: `1`
- Version name: `0.1.0`
- Minimum SDK: `24`
- Target SDK: `37`
- Source fingerprint:
`8339812414061c6090b91f0abfe3562633926b4e72159885f57e7bd4000d2555`
The source fingerprint stored next to the artifact matched a fresh local
fingerprint after the build.
## Upload certificate
- SHA-256:
`A5:74:2B:AE:70:C6:D0:34:E3:75:44:B6:2E:37:A3:75:C0:E0:05:64:74:50:F4:0F:29:B2:A9:84:F9:FD:B8:FB`
- SHA-1:
`8C:84:D5:CA:2F:B7:EA:2B:7E:08:2D:D1:CD:E8:AC:60:56:AA:1B:3C`
This upload certificate is not the Google Play App Signing certificate. After
the first upload, record the Play-generated certificate separately and add its
fingerprints to production Google/Firebase configuration and the production
App Links association.
## Validation evidence
- `bundletool` validation passed.
- Release unit tests and Android lint passed.
- R8 release build completed successfully.
- APK and AAB signing verification passed.
- Universal APK generated from this AAB:
`android/dist-release-20260801-final/who-need-help-release-universal.apk`
- Universal APK SHA-256:
`cf8bf8001b02447fb63ee73b3d8dd980485c38113cc7e0f67705690afa64f79c`
- The universal APK was installed on the authorised physical Android 16 / API
36 device and cold-started successfully.
- The production origin rendered correctly on the device.
- `https://whoneedhelp.com/safety` opened in the installed production app.
- No application crash or TLS/SSL/WebView load failure was observed in the
release smoke-test log.
- The complete repository quality run passed 414 tests plus compiler, format,
xref, Credo, Sobelow, Dialyzer, dependency audit, container, Compose, Helm,
migration, rollback, observability, and image-security gates.
## First Play Console session
1. Create **Who Need Help** as an app (not a game), free, default language
English (United States), support email `contact@whoneedhelp.com`.
2. Accept the policy, export-law, and Play App Signing declarations.
3. Complete the prepared store listing and App content sections using
`android/play-store/` and `android/store-assets/`.
4. Upload only the AAB identified above to an internal-testing release first.
5. Install the Play-delivered build from the internal-test opt-in link and
repeat the production-origin, sign-in, notification, location, and App Link
smoke tests.
6. Record the Play App Signing SHA-1 and SHA-256 before starting the closed
test.
7. Start a closed test with at least 12 continuously opted-in testers for at
least 14 days before requesting production access.
Official references:
- https://support.google.com/googleplay/android-developer/answer/9859152
- https://support.google.com/googleplay/android-developer/answer/9842756
- https://support.google.com/googleplay/android-developer/answer/9845334
- https://support.google.com/googleplay/android-developer/answer/14151465