Play App Signing, mandatory for bundles, uses two keys: your upload key, and Google's app signing key for the APKs phones install. For new apps Google generates "quantum-ready, hybrid" signing keys: RSA 4096-bit plus post-quantum ML-DSA-65, which Android 17 checks through APK Signature Scheme v3.2.

Phones see only the app signing certificate, so assetlinks.json (Android App Links) must list its SHA-256 from the Play Console 1 , or App Links fail in production.
From 31 August 2026, new apps and updates must target Android 16 (API 36), and existing apps at least API 35 to stay available to new users (an extension to 1 November 2026 can be requested); Capacitor 8 243,123 targets 36. Apps targeting API 35 or higher must also support 16 KB memory pages, and from 1 February 2027 updates that don't cannot be released. BookNest's native libraries come from its plugins, so check them:
APK=app/build/outputs/apk/release/app-release.apk
zipalign -c -P 16 -v 4 $APK | grep -E "arm64.*sqlcipher|Verification"
unzip -o -q $APK lib/arm64-v8a/libsqlcipher.so -d build/abi
objdump -p build/abi/lib/arm64-v8a/libsqlcipher.so | grep -c "LOAD.*align 2\*\*14"7241728 lib/arm64-v8a/libsqlcipher.so (OK) Verification successful 3
zipalign checks each library's 16 KB boundary in the APK; the 3 counts SQLCipher 566,000 's ELF load segments aligned to 2**14 (16 KB), which is all of them.