Skip to content

PocketVault v2.4.0

Choose a tag to compare

@greyfreedom greyfreedom released this 05 Aug 03:30

PocketVault v2.4.0

This is the official Play App Signing build generated from the same Android App Bundle published on Google Play.

  • Version name: 2.4.0
  • Version code: 9
  • Package name: com.turisla.hellopocket
  • Source tag: v2.4.0
  • Source commit: f18efacabbc7be7bd93a31197a0d5b5738112f26
  • Distribution artifact: Play-generated signed Universal APK
  • Play App Signing certificate SHA-256: 80:D6:DE:92:50:30:84:33:55:BE:73:7D:49:F8:F6:A4:16:85:5A:B6:CD:59:44:5A:AC:93:F2:7C:64:10:E7:F1
  • Uploaded AAB SHA-256: 7fcc0aeb66edc1e3c5adaacaae3216afcb0f48edbb72e9c1f34a6ecf7f7c461d
  • Universal APK SHA-256: b094dc1c9a9c80e9e82d58fbcaaca890d4c7da2866896c6f9b8b76e62e7b8ccf

Changes

Added

  • Apache-2.0 open-source release materials, security policy, contribution guidance, and bilingual documentation.
  • Public privacy-policy deployment files and an in-app open-source licenses screen.
  • CI checks for compilation, unit tests, lint, privacy-policy synchronization, and the absence of network/Firebase declarations.
  • Bounded automatic backup retention, safer repository error handling, and hardened vault import validation.

Changed

  • New and re-keyed vaults use 600,000 PBKDF2-HMAC-SHA256 iterations; lower historical parameters remain only for legacy compatibility.
  • Google Play and GitHub distribute the same Play App Signing identity; GitHub receives the Play-generated Universal APK from the same uploaded AAB.
  • Debug builds use a distinct .debug application identifier and cannot overwrite the official release.
  • Video thumbnail decoding and Compose side effects were hardened to reduce resource and lifecycle risks.

Removed

  • Android Internet permission.
  • Firebase, Crashlytics, analytics, telemetry, and remote log reporting.

Fixed

  • Automatic backup growth is capped at five files and 1 GiB total.
  • Repository failures are converted to explicit UI states.
  • Several localization and backup-warning inconsistencies.

Verification

The attached APK was downloaded from Google Play Console, carries a verified Source Stamp, and is signed with the official Play App Signing certificate.
The Google Play and GitHub distributions use the same package name and signing identity.

Only the Play-generated Universal APK is attached to this release. The AAB is retained locally for traceability and is not distributed as an installable GitHub asset.