feat(release): production signing in build.yml + F-Droid metadata filled

- build.yml: use production keystore (KEYSTORE_BASE64) on tag pushes,
  fall back to debug key for PRs/branch builds — build.gradle already
  reads RELEASE_STORE_FILE env var so no Gradle changes needed
- distribution/fdroid-submission/metadata.yml: filled
  AllowedAPKSigningKeys with actual SHA-256 fingerprint, commit tag
  updated to v0.3.1, version bumped to 0.3.1
- app.json: bump version 0.2.3 → 0.3.1, versionCode 1 → 2
- Add eas.json + EAS README for iOS App Store builds
- Add fastlane/metadata/android for Play Store / F-Droid graphics
- Add distribution docs: applestore, fdroid, market, playstore,
  security, threat-model, opencode-site-deploy

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Dennis V
2026-05-26 01:26:35 +00:00
parent 2dd49117af
commit b8fb390f5c
21 changed files with 1322 additions and 11 deletions

View File

@@ -74,9 +74,9 @@ RepoType: git
Repo: https://github.com/dzianisv/opencode-mobile
Builds:
- versionName: '1.0.0'
versionCode: 1
commit: <FIRST_GITHUB_RELEASE_TAG>
- versionName: '0.3.1'
versionCode: 2
commit: v0.3.1
subdir: android
sudo:
- apt-get update
@@ -97,11 +97,11 @@ Builds:
# AllowedAPKSigningKeys pins our release signing key.
# F-Droid will serve our pre-signed APK rather than re-signing with their key.
# This requires reproducible builds (identical output across machines).
AllowedAPKSigningKeys: <SIGNING_KEY_SHA256_FINGERPRINT_LOWERCASE_NO_COLONS>
AllowedAPKSigningKeys: 0c259d94e0ffea5d6319614b229d4b6bdc22de1f56e38e76948398d2df6aa099
AutoUpdateMode: Version v%v
UpdateCheckMode: Tags
UpdateCheckData: https://raw.githubusercontent.com/dzianisv/opencode-mobile/main/app.json|"version":\s*"([^"]+)"|.|.
CurrentVersion: '1.0.0'
CurrentVersionCode: 1
CurrentVersion: '0.3.1'
CurrentVersionCode: 2