zapstore / zapstore-cli

https://zap.store
MIT License
5 stars 1 forks source link

Detect F-Droid APK signature #13

Open franzaps opened 4 months ago

franzaps commented 4 months ago

We should be avoiding F-Droid signed packages as much as possible (unless it's the only APK the dev puts outside of big tech)

franzaps commented 4 months ago

Also reject debug certs

franzaps commented 3 months ago

Google Play cert SHA-256: 3257d599a49d2c961a471ca9843f59d341a405884583fc087df4237b733bbd6d

franzaps commented 3 months ago

Check https://floss.social/@IzzyOnDroid/110856024209846632

franzaps commented 2 months ago

Only applies to APKs we process. Developers can sign whatever they like

franzaps commented 2 months ago

F-Droid certificate hash: 3705f184cb67d683e76ecc203cc9cc357e6448c50e59002419085b4c286df0e8