Use case
I'm installing this app via Obtanium / sideloading, and I'd like to make sure the APK I install is genuinely signed by you (and not a tampered or repackaged build).
To verify this, I use a certificate-fingerprint check (e.g., AppVerifier, or keytool -printcert -jarfile app.apk on desktop). For that to work, I need the signing certificate's fingerprint published somewhere I can compare against.
Proposed solution
Please add the SHA-256 fingerprint of the signing certificate (SHA-1 is a fine bonus) to the README and/or the Releases page, e.g.:
Use case
I'm installing this app via Obtanium / sideloading, and I'd like to make sure the APK I install is genuinely signed by you (and not a tampered or repackaged build).
To verify this, I use a certificate-fingerprint check (e.g., AppVerifier, or
keytool -printcert -jarfile app.apkon desktop). For that to work, I need the signing certificate's fingerprint published somewhere I can compare against.Proposed solution
Please add the SHA-256 fingerprint of the signing certificate (SHA-1 is a fine bonus) to the README and/or the Releases page, e.g.: