Releases: SloMR/Rootect
Release list
1.1.0
Rootect v1.1.0
A detection and accuracy release: a second channel for the repackaging check, two new posture signals, and a way to see which checks could not complete.
Install
Kotlin DSL (build.gradle.kts):
dependencies {
implementation("io.github.rootect:rootect-core:1.1.0")
}Groovy DSL (build.gradle):
dependencies {
implementation 'io.github.rootect:rootect-core:1.1.0'
}What's new
SIGNATURE_MISMATCHchecks the APK bytes too. Native code reads the APK Signing Block and hashes the signer Android would use on the running version (v3.1, then v3, then v2), alongside PackageManager. The result travels inside the tamper-tagged native scan.DEVELOPER_OPTIONS_ENABLEDandADB_ENABLED. TwoWEAKenvironment signals for Developer options and USB debugging. Posture, not proof — they never feedisRooted.RootectReport.inconclusiveSources. Names which checks could not complete (InconclusiveCheck), so a signing check that could not run can be told apart from a denied/procread.- Reference attestation server. Keeps serving the last good revocation list through a Google outage and fails closed only once the list is too old or was never fetched. Client signals are echoed as
reportedSignalsfor your backend to weigh, not judged.
Behaviour changes
- An unreadable signing certificate now counts as inconclusive rather than
SIGNATURE_MISMATCH. A definite mismatch from either PackageManager or the APK still fires. - Devices with Developer options or USB debugging on score slightly higher overall, through the two new
WEAKsignals. - Two new
SignalIdvalues. AwhenoverSignalIdneeds anelsebranch or cases for them.
Documentation
Full changelog: 1.0.0...1.1.0
License
Apache 2.0.
1.0.0
Rootect v1.0.0
First public release of Rootect — environment-integrity evidence for Android apps.
It detects root (Magisk / KernelSU / APatch, including when actively hidden), runtime instrumentation (Frida, Xposed / LSPosed, Zygisk), app tampering and repackaging, debuggers, and emulators.
Rootect reports evidence, not verdicts — the host app decides whether to block, degrade, or log.
Install
Kotlin DSL (build.gradle.kts):
dependencies {
implementation("io.github.rootect:rootect-core:1.0.0")
}Groovy DSL (build.gradle):
dependencies {
implementation 'io.github.rootect:rootect-core:1.0.0'
}No third-party dependencies, no permissions, no Google Play requirement. minSdk 24. Native code ships for arm64-v8a, armeabi-v7a, and x86_64.
The public API is fully Java-callable — see Integration.
Highlights
- Native by default. Detection runs on raw syscalls in a stripped native library — bypassing it means reverse-engineering, not writing a five-line hook.
- Hardware attestation. Opt-in Keystore attestation, designed to be verified server-side where it can't be faked.
- Honest about its limits. Every signal documents what defeats it — no overclaiming.
Documentation
License
Apache 2.0.