3627e9f9cf
The apksigner step relied on auto scheme selection, which produced an APK carrying invalid v1 (JAR) signature files: META-INF/*.SF and *.RSA were present but failed v1 verification (apksigner reports `v1 scheme: false` while v2/v3 verify). Android installs such an APK fine via v2/v3, but Obtainium parses the legacy v1 certificate at install time, gets an empty cert list, and crashes with: RangeError (length): Invalid value: valid value range is empty: 0 This is why the app adds fine in Obtainium (Gitea API only) but fails on install (APK parse). minSdk is 26, so v1/JAR signing is unnecessary — sign explicit v2+v3 only (matching modern Android tooling for minSdk >= 24) and pass --min-sdk-version 26. Adds a post-sign guard that fails the build if any META-INF v1 signature files remain. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>