Repository navigation
Releases: AlicanAkyol/nativekeel
Releases · AlicanAkyol/nativekeel
Release list
v0.1.30
- New (store): SDKs on Apple's privacy-manifest list in versions without one (ios/Podfile.lock), with the React Native pod that pulls each in. First-version table generated from the CocoaPods specs (scripts/privacy-sdk-table.mjs). Binary pods that cannot be verified are left out; React Native's Hermes is not Apple's 'hermes'. 24 of 116 apps with a Podfile.lock.
v0.1.29
- New (store): sign-up in the app (Firebase, Supabase, Amplify, Appwrite, Clerk, /signup API) with no account deletion anywhere: App Store 5.1.1(v) and Google Play account deletion. 43 apps.
- New (store): Google/Facebook login on iOS without Sign in with Apple or an equivalent (guideline 4.8, exceptions listed). 11 apps.
- Measured, not shipped: App Tracking Transparency (missing prompt is lost ad revenue, not a rejection).
v0.1.28
- New (stability): an API address that only exists on the developer's machine (10.0.2.2, LAN IPs, localhost, ngrok) used outside development-only branches. Settings screens, placeholders, named local fallbacks, local-service probes and 'use server' code are excluded. 21 apps in the test set.
v0.1.27
- New (store): components with an intent-filter and no android:exported in apps targeting < 31 (a build error from 31; Play requires 36). Plan fixes them before the target SDK step. 107 apps in the test set.
v0.1.26
- New: packages off the versions the Expo SDK pins (bundledNativeModules.json from node_modules, else unpkg with only the expo version). Major = high, minor = medium, patch = low. 144 of 390 Expo apps with a lockfile.
- New: native libraries whose react-native peer range starts above the installed React Native (lower bounds only).
- TLS: react-native-blob-util sharedTrustManager judged by trusty usage (unused: not reported; setting: high; always: critical).
- Privacy page, README and SECURITY.md list every network request.
v0.1.25
- New (security, MASVS-AUTH): Supabase public tables created in supabase/ migrations without row level security. Commented-out enables do not count; other schemas and RLS loops are recognised. 3 of 15 Supabase apps in the test set.
- New (store): permissions Google Play restricts (READ_MEDIA_IMAGES/VIDEO, MANAGE_EXTERNAL_STORAGE, REQUEST_INSTALL_PACKAGES, ACCESS_BACKGROUND_LOCATION, SMS/call log, USE_FULL_SCREEN_INTENT, USE_EXACT_ALARM), from the manifest and app.json; tools:node="remove" and blockedPermissions respected. High for photo/video access next to a photo picker library. 24 apps.
v0.1.24
- Private keys need a key body (form placeholders, elided samples and header-only constants are not reported). Real keys still found.
- Reanimated 4 + worklets: not reported when the lockfile or node_modules has react-native-worklets (npm 7+/pnpm install peers).
- Test/sample keystores and their passwords used as local fallbacks are not release keys.
- MD5 password hashing required by the Subsonic API: low, explained.
- 90-second network budget: a slow registry ends the scan with a warning instead of hanging.
- Test set: 653 apps, with recently pushed apps added weekly.
v0.1.23
- Core SafeAreaView with target SDK 35+ (or Expo SDK 52+): medium, explaining Android 15 edge-to-edge (the core component only applies to iOS). 29 apps in the test set.
v0.1.22
- Auth tokens in AsyncStorage/MMKV found by value too (constant keys, objects containing a token). Push/device tokens and .web. files are skipped. 13 apps in the test set instead of 4.
- README links the corpus write-up.
v0.1.21
- Correction: Google Play blocks updates without 16 KB page support from 2027-02-01 (developer.android.com/guide/practices/page-sizes, updated 2026-09-16). Until then 16 KB findings are high and give that date; they become critical on their own from 2027-02-01.