NativeKeel ยท React Native fixes

You uploaded an APK or Android App Bundle that was signed in debug mode

Updated 2026-10-10

What it means. Google Play only accepts uploads signed with your own key. The React Native template signs release builds with the debug key, which is the same public key on every machine:

release {
    // Caution! In production, you need to generate your own keystore file.
    signingConfig signingConfigs.debug
}

How to fix it. Create an upload key once and keep it out of the repository:

keytool -genkeypair -v -storetype PKCS12 -keystore upload.keystore -alias upload -keyalg RSA -keysize 2048 -validity 10000

Put the passwords in ~/.gradle/gradle.properties (or CI secrets), not in the project, then sign the release build with it in android/app/build.gradle:

signingConfigs {
    release {
        storeFile file(MYAPP_UPLOAD_STORE_FILE)
        storePassword MYAPP_UPLOAD_STORE_PASSWORD
        keyAlias MYAPP_UPLOAD_KEY_ALIAS
        keyPassword MYAPP_UPLOAD_KEY_PASSWORD
    }
}
buildTypes {
    release {
        signingConfig signingConfigs.release
    }
}

Build with ./gradlew bundleRelease and upload the .aab. With Play App Signing, Google re-signs for users and this is your upload key.

If you build with EAS or sign in CI (Fastlane, a signing action), the signing happens there and the Gradle setting does not matter.

How common it is. In our scan of 653 open-source React Native apps, 62 sign release builds with the debug key and do not sign them elsewhere. npx nativekeel reports it, together with signing passwords or keystores committed to the repository.

Check your whole app in one command: npx nativekeel
Free, runs locally (your code is not uploaded), no account. It reports this and 80 other upgrade, store, crash and security problems.

Sources