What?
Don't assume that the APKs are generated by GitHub's CI, anyhow, anything can be uploaded as a release
In any case, there's for sure no GitHub certificate added to the APKs
It seems to not check it automatically, though?
- uses: JS-DevTools/npm-publish@v2 with: token: ${{ secrets.NPM_TOKEN }} access: public provenance: true
What?
Don't assume that the APKs are generated by GitHub's CI, anyhow, anything can be uploaded as a release