Fixed signing identity
Production APKs must use the same long-term Owner signing certificate. The fingerprint is pinned in Admin settings.
Only Owner-published applications are distributed here.
Production APKs must use the same long-term Owner signing certificate. The fingerprint is pinned in Admin settings.
The Android build pipeline verifies the APK with apksigner and emits a release manifest. The website compares that manifest to the uploaded APK SHA-256 before publishing.
For outside-Play distribution, Android Developer Verification status can be recorded by the Owner after the package and signing key are registered.