Releases: 0x56dev/0x56erify
Release list
v0.1.3 - Multi-checksum parsing fix
Bug-fix release for pasting several checksum lines into the expected-hash field. Verified manually on a physical device.
Fixed
- Pasting more than one checksum line (for example, a whole
SHA256SUMSfile) used only the first hash and ignored the rest. If your file's line wasn't first, a genuine file showed MISMATCH. The expected-hash field is now read line by line:- A single bare hash or
<hash> filenameline works as before (tabs, extra spaces, mixed case, the*filenamebinary-mode marker and Windows line endings are all fine). - Several different hashes are rejected with a clear message: "Several different SHA-256 hashes were pasted. Paste only the line for this file." Repeated lines with the same hash are still accepted.
- Lines that aren't checksum lines (for example, text after the hash) are now rejected instead of being silently ignored.
- A single bare hash or
Thanks to volunteer tester @gitubpatrice for reporting this.
This build
- 39/39 unit tests passing (14 new tests for multi-line input)
- Clean release build (
assembleRelease), lint-vital passed - Signed with the same key as previous releases; no dependency-info signing block
- No
INTERNETpermission; no UI or feature changes beyond this fix
versionCode: 4 · versionName: 0.1.3
APK SHA-256: 1d493463e651843baba4a30e64611038f1fb3cee463684715b96e472493fdb1a
v0.1.2 - Build/release metadata fix
Build/release metadata fix. No app functionality changed.
Fixed
- Disabled Android Gradle Plugin's dependency metadata block (
dependenciesInfo.includeInApk/includeInBundle). This block embeds a list of compile-time dependencies into the APK for Play Console reporting; it's irrelevant off Play and was flagged by F-Droid's reproducible-build scanner as an unwanted extra signing block in the v0.1.1 binary.
Verified before release
- 25/25 unit tests passing
- Clean release build (
assembleRelease), lint-vital passed - Confirmed via
apksigtooland F-Droid's own scanner code that the "Dependency Info Block" (APK signing-block pair ID0x504b4453) present in v0.1.1 is absent from this build - Verified F-Droid's real reproducible-build comparison (apksigcopier-based) succeeds against this signed binary from a from-source build at the tagged commit, before this release was published
versionCode: 3 · versionName: 0.1.2
APK SHA-256: 1491f9b6899981c1f998654c296985f1ca6deded286061ef6b4f3878cfc86e31
v0.1.1 - Paste-parsing fix
Bug-fix release. Verified manually on a physical device.
Fixed
- Expected-hash validation now correctly accepts hashes copied directly from
sha256sum/sha512sumterminal output (e.g.<hash> file.iso), including cases with tabs or multiple spaces before the filename. Bare hashes, mixed case, and surrounding whitespace/newlines continue to work as before.
No functional changes beyond this fix; no UI or feature changes.
This build
- 25/25 unit tests passing
- Clean release build (
assembleRelease), lint-vital passed - Dependencies: AndroidX/Jetpack Compose + Kotlin coroutines only — no Google Play Services, Firebase, analytics, ads, or tracking
- No
INTERNETpermission, no unnecessary storage permissions - APK is self-signed for manual installation/testing; F-Droid's own build server signs its distributed build independently
versionCode: 2 · versionName: 0.1.1
APK SHA-256: e335023a8d019ac065e423740abd1a6f9bf0ad7ffab4131400a5b76ba8703cdc
v0.1.0 - Initial release
Initial verified release of 0x56erify — a minimal, offline checksum verification app for Android.
Verified manually on a physical Samsung Galaxy S26 Ultra: file selection, SHA-256 hashing, MATCH on correct hash, MISMATCH on a single changed character, clear validation error on malformed input, and correct UI behavior throughout.
Features
- Pick a file via the system document picker (SAF)
- Compute SHA-256 or SHA-512, streamed and off the UI thread
- Paste an expected hash for a MATCH / MISMATCH result
- Copy or share the computed hash
- Fully offline: no accounts, no analytics, no ads, no tracking, no
INTERNETpermission
This build
- 13/13 unit tests passing
- Clean release build (
assembleRelease), lint-vital passed - Dependencies: AndroidX/Jetpack Compose + Kotlin coroutines only — no Google Play Services, Firebase, or proprietary SDKs
- APK is self-signed for manual installation/testing; F-Droid's own build server will sign its distributed build independently
APK SHA-256: 095421e03d09bb588f92b0b6953f785f285c4e48e273e08fb06e03ca29640341