Mango Player Android 0.7.19 (build 52)
Release status
- Artifact verification: passed, including signature, native inventory, 16 KB alignment and Android 14 smoke launch.
- Play exclusions: libVLC, Jellyfin,
libffmpegJNI.soandlibpostproc.soare absent. - Security: FFmpeg n8.1.2 replaces the CVE-2026-8461-affected FFmpeg 8.0 payload.
- Product behavior: downloads remain available; this compliance change does not remove the feature.
- Source evidence: exact pins and verified archives are published below.
- Independent legal closure: open because the supplier does not publish its exact modified third-party FFmpegKit build scripts. Public Store clearance is not declared by this page.
Binary identity (binaries are not hosted here)
Product commit: d01490723b63632748ff579066228787b3e266a7
- Google Play AAB: 168,177,962 bytes โ SHA-256
3E3AA815258263BB43D20E18F056B739F9BEDF34FD5FA01725FC60ED79811B83 - Native debug symbols: 18,784,626 bytes โ SHA-256
6833512669E0CC446AB49C0DA67E6DBB435A1D3E43E53F284EB0C79697AAD556 - Signing certificate SHA-256:
68:44:6E:5C:48:39:01:00:A6:70:FE:CC:E8:99:A0:EC:F5:38:01:1B:19:5E:F3:51:A0:56:C9:BE:15:C0:B3:B5
Release documents
Pinned source evidence
The archives listed in source-index.json are mirrored under sources/. They cover the exact FFmpegKit wrapper/native commits, FFmpeg versions, media-kit build scripts and the non-GPL media-kit dependency set.
The archived arthenica v6.0 build system is reference evidence, not a claim that it is the supplier's unpublished modified build recipe. This distinction keeps the remaining review item visible.
Compliance evidence, not legal advice. Contact: legal@mangoplayer.app.