The signing key is on this machine now, so 0.4.0 is signed and archived like
every release before it. The certificate is the same one:
CN=Ganjoor for Android, O=anas-rashid, C=PK
SHA-256 d3b5a144b600dd6d9ae8236f0a1bd630767e88d7eaa1573edaadbf8e651fe494
verified against 0.3.0's before archiving, which is the point of checking: a
different key would have forced every existing install to be removed first, and
releases/README.md promises that never happens.
The 0.3.0 row also gets its real commit; it still said HEAD, which stops meaning
anything the moment another release lands on top of it.
metadata/com.ganjoor.android.yml is the recipe F-Droid's build server uses,
kept with the source it describes rather than only in a fork of fdroiddata.
UpdateCheckMode is Tags, so each new tag is picked up without editing it again.
F-Droid signs with their own key, which is why the release build has to succeed
with no keystore present.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>