Record versionName, versionCode, package name, file SHA-256, signing-certificate SHA-256, build time, download source, and test time. Keep the original, unhardened control, and hardened candidate as separate artifacts. A filename can help your internal workflow, but it is not a reliable sample identifier.
Verify the signature, clean installation, upgrade installation, launch, and critical product flows before external scanning. A package that cannot be installed, has an unexpected signing chain, or fails a critical flow has a release defect that should be corrected before anyone argues about a false positive.