v0.3.3
Installs in place over any earlier release (identity and settings kept) via the automatic update prompt, Check for updates, or sideload.
If you are already on 0.3.2, this update changes nothing you can see. No app source changed between 0.3.2 and 0.3.3 — the binary is functionally identical. The changes are to how releases are built and verified. Updating is harmless but optional.
Changes since v0.3.2
- A universal APK is now published. One artifact containing all three ABIs, so a first-time installer who is unsure which build they need can take
-universal.apkand have it install on any device. It is ~40 MB against ~18 MB forarm64-v8a, so prefer the ABI-specific build if you know yours. The in-app updater always picks the ABI-specific one, whichever you installed. - The per-ABI packaging check now works. The release script's assertion that a per-ABI APK contains only its own ABI had never once fired: a shell pipeline quirk turned its failure into a pass, and against a deliberately mispackaged APK it wrongly passed 20 out of 20 runs. It is fixed and tested. 0.3.2's per-ABI APKs were never actually verified by it; 0.3.3's are the first that have been.
- fips2go is now on Zapstore, with the APK signing certificate cryptographically linked to the publisher's Nostr identity.
Install
Sideload the APK matching your device (adb install -r or open it on the phone); min SDK 26 (Android 8.0). Verify the download against the matching .sha256, or update from within the app.
- universal — all three ABIs in one file. Installs anywhere; larger. Use this if unsure.
- arm64-v8a — every 64-bit ARM phone from roughly 2016 on; the device-verified build.
- armeabi-v7a — old 32-bit phones. Compiles and packages; not exercised on real 32-bit hardware.
- x86_64 — Android emulator, Chromebooks.
Release APKs are signed with the key whose certificate SHA-256 is
aa905e32bd0058874d252990abba26c78ddd8fca018195ebd1cd232a99a7a8e1 — check a
fresh download with apksigner verify --print-certs <apk>. This matters most on a
first install: there is no previously installed signature for Android to
compare against, so the checksum and this fingerprint are the only things
identifying a genuine build. Subsequent updates are enforced against the key
automatically.
Caveats
Only arm64-v8a is exercised on real hardware. armeabi-v7a compiles and packages but has not been run on a 32-bit device; x86_64 is emulator-verified.