aboutcode-org / scancode.io

ScanCode.io is a server to script and automate software composition analysis pipelines with ScanPipe pipelines. This project is sponsored by NLnet project https://nlnet.nl/project/vulnerabilitydatabase/ Google Summer of Code, nexB and others generous sponsors!
https://scancodeio.readthedocs.io
Apache License 2.0
119 stars 88 forks source link

Android Device D2D: Clarify how to analyze Android special file formats #1374

Open pombredanne opened 2 months ago

pombredanne commented 2 months ago

Android has many unique formats such as:

We need to get a good handle on what these are and how they relate to the other formats to decide aht to do with each for the analysis. Some formats may contains the same thing but with different optimizations applied. Or in some cases we may not have multiple variants.

BANG and lief may help here for sure.

chinyeungli commented 2 months ago

In short, I think we only need to deal with .dex files