What happened to your signing key?
- Linguagem predominante
- TypeScript
- Estrelas
- 42
- Forks
- 4
- Métricas de merge de PRs
- Nenhum PR com merge em 30d
Descrição
Release 1.11.2 was rejected by our updater:
```
! com.akylas.conty_40.apk is signed by a certificate that is not allowed:
'51b2b90f82394180cd72794e56c654f861482c1c0dc5da86f2d615c56a331fda'; needs to be quarantined
```
There's no release note, and the fastlane changelog for this release is an empty file. Seeing that the new certificate has all fields in the DN explicitly set to "Unknown", while the original one had them properly set, makes this change looking quite suspicious.
We have temporarily disabled update checks, until this has been clarified (folks could not "update" to it anyway, as Android would reject the update as well).
Guia de contribuição
Nenhum guia de contribuição indexado para este repositório
Direção de pesquisa
Start by comparing the signing certificate on release 1.11.2 with the original certificate and reviewing the empty fastlane changelog for that release. Trace the updater's certificate validation entry point and document the certificate's provenance and a safe resolution before update checks are restored.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- android
- Domínio
- mobile, release, security
- Tipo de issue
- Bug
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Status de atividade
- Pouca atividade
- Clareza
- Precisa de esclarecimento
- Facilidade para iniciantes
- 45/100