Is it safe to store the file .well-known/assetlinks.json in a public repo? Since the statement list asks for a signing key, it seems like this is a sensitive file?
Google's official generator does not ask for a signing key, just the fingerprint of the associated app. If some tool is asking for the signing key you might have encountered a phishing attempt.
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With