Release safety

Distribution checklist

The website should make safe installs boring: signed artifacts, checksums, exact runtime pairing, and clear rollback instructions.

Before publishing

  • Release build only; never debug APK.
  • Version metadata committed and tagged.
  • Compatible runtime tag pinned.
  • APK/AAB SHA256 generated and published.
  • Installer script reviewed for the selected runtime tag.
  • Install docs updated with known caveats.

Preferred channels

  1. Firebase App Distribution for non-technical testers.
  2. Private GitHub Releases for technical testers.
  3. commaview.com HTTPS page once auth/visibility is decided.
  4. Google Play closed testing when policy paperwork is worth it.