01 Signature & Signing
- SHA-256 fingerprint computed against the entire archive
- Original developer certificate recovered from Google Play metadata
- v1 / v2 / v3 / v3.1 signature chain validation
- JAR manifest signature parity across every entry
- Re-signing detection via cert-hash diff against last known-good
- Key rotation events flagged when cert < 24h old