--release switches Gradle 19,597 to the release build type: no debugger, no debuggable flag, and, since cordova-android 10, an Android App Bundle (.aab) rather than an APK unless you ask otherwise. With build.json naming the key and the passwords passed after --, the bundle comes out signed:
cordova build android --release -- --storePassword="$BOOKNEST_STORE_PASS" \
--password="$BOOKNEST_STORE_PASS" | grep -E "keystore|BUILD SUCCESSFUL|\.aab"
keytool -printcert -jarfile platforms/android/app/build/outputs/bundle/release/app-release.aab |
grep -E "Owner|SHA256:"...
Reading the keystore from: .../keys/booknest-upload.jks
BUILD SUCCESSFUL in 9s
BUILD SUCCESSFUL in 50s
.../platforms/android/app/build/outputs/bundle/release/app-release.aab
Owner: CN=BookNest Team, O=Example Books, L=Kota Kinabalu, C=MY
SHA256: AA:F4:72:D5:8E:4E:5D:A3:50:ED:B3:BE:06:E6:AD:93:2A:63:DE:8C:71:8A:C0:69:61:40:33:33
:A7:DB:72:C9Without the passwords the build fails at :app:signReleaseBundle (Android Build Failures); without build.json it produces an unsigned bundle, which Play rejects. Before you upload:
Bump the version. Play refuses a versionCode it has seen. Raise version in config.xml (1.0.1 gives
or pass -PcdvVersionCode as release does (Build Batch Files).
Leave WebView debugging off. Release builds disable it unless you set InspectableWebview.
Test the release build itself, as an APK on a device (Build Batch Files).