Archive the signed 0.4.0, and add the F-Droid recipe #8

Closed
anas wants to merge 0 commits from release/archive-0.4.0-apk into main
Owner

The signing key is on this machine now, so 0.4.0 is signed and archived like every release before it.

The certificate is the same one

CN=Ganjoor for Android, O=anas-rashid, C=PK
SHA-256 d3b5a144b600dd6d9ae8236f0a1bd630767e88d7eaa1573edaadbf8e651fe494

Verified against 0.3.0's before archiving — byte-identical digest. That is the whole point of the check: a different key would have forced every existing install to be uninstalled first, losing bookmarks and downloaded poets, and releases/README.md promises that never happens.

What's in it

  • releases/ganjoor-0.4.0.apk — 31.7 MB, signed, R8-minified
  • checksum 1c64cefa0fb2b51bf73386460ec1b88bda3e20832fa6926c2f7f1fb863ab9fc7
  • the 0.4.0 row in releases/README.md
  • the 0.3.0 row's real commit (5d12a1c) — it still said HEAD, which stops meaning anything the moment another release lands on top

F-Droid recipe

metadata/com.ganjoor.android.yml is what F-Droid's build server uses, kept with the source it describes rather than only in a fork of fdroiddata:

License: MIT
RepoType: git
Repo: https://github.com/anas-rashid/ganjoorandroid.git
Builds:
  - versionName: 0.4.0
    versionCode: 6
    commit: v0.4.0
    subdir: app
    gradle: [yes]
AutoUpdateMode: Version
UpdateCheckMode: Tags

UpdateCheckMode: Tags means each new tag is picked up without editing this again.

Note it builds with no keystore — F-Droid signs with their own key, which is exactly why app/build.gradle.kts makes signing optional. Nothing secret is in this PR; keystore.properties and *.jks are gitignored and I confirmed neither was staged.

The signing key is on this machine now, so 0.4.0 is signed and archived like every release before it. ## The certificate is the same one ``` CN=Ganjoor for Android, O=anas-rashid, C=PK SHA-256 d3b5a144b600dd6d9ae8236f0a1bd630767e88d7eaa1573edaadbf8e651fe494 ``` Verified against `0.3.0`'s **before** archiving — byte-identical digest. That is the whole point of the check: a different key would have forced every existing install to be uninstalled first, losing bookmarks and downloaded poets, and `releases/README.md` promises that never happens. ## What's in it - `releases/ganjoor-0.4.0.apk` — 31.7 MB, signed, R8-minified - checksum `1c64cefa0fb2b51bf73386460ec1b88bda3e20832fa6926c2f7f1fb863ab9fc7` - the `0.4.0` row in `releases/README.md` - the `0.3.0` row's real commit (`5d12a1c`) — it still said `HEAD`, which stops meaning anything the moment another release lands on top ## F-Droid recipe `metadata/com.ganjoor.android.yml` is what F-Droid's build server uses, kept with the source it describes rather than only in a fork of `fdroiddata`: ```yaml License: MIT RepoType: git Repo: https://github.com/anas-rashid/ganjoorandroid.git Builds: - versionName: 0.4.0 versionCode: 6 commit: v0.4.0 subdir: app gradle: [yes] AutoUpdateMode: Version UpdateCheckMode: Tags ``` `UpdateCheckMode: Tags` means each new tag is picked up without editing this again. Note it builds with **no keystore** — F-Droid signs with their own key, which is exactly why `app/build.gradle.kts` makes signing optional. Nothing secret is in this PR; `keystore.properties` and `*.jks` are gitignored and I confirmed neither was staged.
anas added 1 commit 2026-10-07 17:18:30 +00:00
The signing key is on this machine now, so 0.4.0 is signed and archived like
every release before it. The certificate is the same one:

  CN=Ganjoor for Android, O=anas-rashid, C=PK
  SHA-256 d3b5a144b600dd6d9ae8236f0a1bd630767e88d7eaa1573edaadbf8e651fe494

verified against 0.3.0's before archiving, which is the point of checking: a
different key would have forced every existing install to be removed first, and
releases/README.md promises that never happens.

The 0.3.0 row also gets its real commit; it still said HEAD, which stops meaning
anything the moment another release lands on top of it.

metadata/com.ganjoor.android.yml is the recipe F-Droid's build server uses,
kept with the source it describes rather than only in a fork of fdroiddata.
UpdateCheckMode is Tags, so each new tag is picked up without editing it again.
F-Droid signs with their own key, which is why the release build has to succeed
with no keystore present.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
anas closed this pull request 2026-10-07 21:21:02 +00:00

Pull request closed

Sign in to join this conversation.
No reviewers
No Label
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: anas/ganjoorandroid#8
No description provided.