androguard / androguard/apk-parser

Support APK signing scheme v4

Open
#2 0 comments 0 reactions 1 assignee Claimed by @ping2A View on GitHub
enhancement
Dominant language
Python
Stars
8
Forks
3
PR merge metrics
No merged PRs in 30d

Description

### Describe what you wanted to do

- please support [APK signing scheme v4](https://source.android.com/security/apksigning/v4)

### Describe what you expected

- it has `is_signed_v4()` method in `apk.py`

### Describe what actually happened

- according to [apk.py#L1569](https://github.com/androguard/androguard/blob/8d091cbb309c0c50bf239f805cc1e0931b8dcddc/androguard/core/bytecodes/apk.py#L1569), the code only checks v1 to v3 scheme, not v4

### System Information

- Androguard Version: 3.4.0a1
- Python Version: 3.8
- Operating System: Ubuntu 20.04LTS

### Further Log Files and Output

- I use androguard via [MobSF](https://mobsf.github.io/docs/#/) with [their official Docker image](https://hub.docker.com/r/opensecurity/mobile-security-framework-mobsf/), and it lacks v4 signature check feature
- I asked it in the MobSF slack and Ajin kindly suggest to report it here

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.