Skip to content

Releases: SloMR/Rootect

Release list

1.1.0

Choose a tag to compare

@SloMR SloMR released this 23 Sep 11:06

Rootect v1.1.0

A detection and accuracy release: a second channel for the repackaging check, two new posture signals, and a way to see which checks could not complete.

Install

Kotlin DSL (build.gradle.kts):

dependencies {
    implementation("io.github.rootect:rootect-core:1.1.0")
}

Groovy DSL (build.gradle):

dependencies {
    implementation 'io.github.rootect:rootect-core:1.1.0'
}

What's new

  • SIGNATURE_MISMATCH checks the APK bytes too. Native code reads the APK Signing Block and hashes the signer Android would use on the running version (v3.1, then v3, then v2), alongside PackageManager. The result travels inside the tamper-tagged native scan.
  • DEVELOPER_OPTIONS_ENABLED and ADB_ENABLED. Two WEAK environment signals for Developer options and USB debugging. Posture, not proof — they never feed isRooted.
  • RootectReport.inconclusiveSources. Names which checks could not complete (InconclusiveCheck), so a signing check that could not run can be told apart from a denied /proc read.
  • Reference attestation server. Keeps serving the last good revocation list through a Google outage and fails closed only once the list is too old or was never fetched. Client signals are echoed as reportedSignals for your backend to weigh, not judged.

Behaviour changes

  • An unreadable signing certificate now counts as inconclusive rather than SIGNATURE_MISMATCH. A definite mismatch from either PackageManager or the APK still fires.
  • Devices with Developer options or USB debugging on score slightly higher overall, through the two new WEAK signals.
  • Two new SignalId values. A when over SignalId needs an else branch or cases for them.

Documentation

Full changelog: 1.0.0...1.1.0

License

Apache 2.0.

1.0.0

Choose a tag to compare

@SloMR SloMR released this 13 Sep 16:22

Rootect v1.0.0

First public release of Rootect — environment-integrity evidence for Android apps.

It detects root (Magisk / KernelSU / APatch, including when actively hidden), runtime instrumentation (Frida, Xposed / LSPosed, Zygisk), app tampering and repackaging, debuggers, and emulators.

Rootect reports evidence, not verdicts — the host app decides whether to block, degrade, or log.

Install

Kotlin DSL (build.gradle.kts):

dependencies {
    implementation("io.github.rootect:rootect-core:1.0.0")
}

Groovy DSL (build.gradle):

dependencies {
    implementation 'io.github.rootect:rootect-core:1.0.0'
}

No third-party dependencies, no permissions, no Google Play requirement. minSdk 24. Native code ships for arm64-v8a, armeabi-v7a, and x86_64.

The public API is fully Java-callable — see Integration.

Highlights

  • Native by default. Detection runs on raw syscalls in a stripped native library — bypassing it means reverse-engineering, not writing a five-line hook.
  • Hardware attestation. Opt-in Keystore attestation, designed to be verified server-side where it can't be faked.
  • Honest about its limits. Every signal documents what defeats it — no overclaiming.

Documentation

License

Apache 2.0.