PocketVault v2.4.0
PocketVault v2.4.0
This is the official Play App Signing build generated from the same Android App Bundle published on Google Play.
- Version name:
2.4.0 - Version code:
9 - Package name:
com.turisla.hellopocket - Source tag:
v2.4.0 - Source commit:
f18efacabbc7be7bd93a31197a0d5b5738112f26 - Distribution artifact: Play-generated signed Universal APK
- Play App Signing certificate SHA-256:
80:D6:DE:92:50:30:84:33:55:BE:73:7D:49:F8:F6:A4:16:85:5A:B6:CD:59:44:5A:AC:93:F2:7C:64:10:E7:F1 - Uploaded AAB SHA-256:
7fcc0aeb66edc1e3c5adaacaae3216afcb0f48edbb72e9c1f34a6ecf7f7c461d - Universal APK SHA-256:
b094dc1c9a9c80e9e82d58fbcaaca890d4c7da2866896c6f9b8b76e62e7b8ccf
Changes
Added
- Apache-2.0 open-source release materials, security policy, contribution guidance, and bilingual documentation.
- Public privacy-policy deployment files and an in-app open-source licenses screen.
- CI checks for compilation, unit tests, lint, privacy-policy synchronization, and the absence of network/Firebase declarations.
- Bounded automatic backup retention, safer repository error handling, and hardened vault import validation.
Changed
- New and re-keyed vaults use 600,000 PBKDF2-HMAC-SHA256 iterations; lower historical parameters remain only for legacy compatibility.
- Google Play and GitHub distribute the same Play App Signing identity; GitHub receives the Play-generated Universal APK from the same uploaded AAB.
- Debug builds use a distinct
.debugapplication identifier and cannot overwrite the official release. - Video thumbnail decoding and Compose side effects were hardened to reduce resource and lifecycle risks.
Removed
- Android Internet permission.
- Firebase, Crashlytics, analytics, telemetry, and remote log reporting.
Fixed
- Automatic backup growth is capped at five files and 1 GiB total.
- Repository failures are converted to explicit UI states.
- Several localization and backup-warning inconsistencies.
Verification
The attached APK was downloaded from Google Play Console, carries a verified Source Stamp, and is signed with the official Play App Signing certificate.
The Google Play and GitHub distributions use the same package name and signing identity.
Only the Play-generated Universal APK is attached to this release. The AAB is retained locally for traceability and is not distributed as an installable GitHub asset.