Skip to content

1.1.0

Latest

Choose a tag to compare

@SloMR SloMR released this 23 Sep 11:06
· 1 commit to main since this release

Rootect v1.1.0

A detection and accuracy release: a second channel for the repackaging check, two new posture signals, and a way to see which checks could not complete.

Install

Kotlin DSL (build.gradle.kts):

dependencies {
    implementation("io.github.rootect:rootect-core:1.1.0")
}

Groovy DSL (build.gradle):

dependencies {
    implementation 'io.github.rootect:rootect-core:1.1.0'
}

What's new

  • SIGNATURE_MISMATCH checks the APK bytes too. Native code reads the APK Signing Block and hashes the signer Android would use on the running version (v3.1, then v3, then v2), alongside PackageManager. The result travels inside the tamper-tagged native scan.
  • DEVELOPER_OPTIONS_ENABLED and ADB_ENABLED. Two WEAK environment signals for Developer options and USB debugging. Posture, not proof — they never feed isRooted.
  • RootectReport.inconclusiveSources. Names which checks could not complete (InconclusiveCheck), so a signing check that could not run can be told apart from a denied /proc read.
  • Reference attestation server. Keeps serving the last good revocation list through a Google outage and fails closed only once the list is too old or was never fetched. Client signals are echoed as reportedSignals for your backend to weigh, not judged.

Behaviour changes

  • An unreadable signing certificate now counts as inconclusive rather than SIGNATURE_MISMATCH. A definite mismatch from either PackageManager or the APK still fires.
  • Devices with Developer options or USB debugging on score slightly higher overall, through the two new WEAK signals.
  • Two new SignalId values. A when over SignalId needs an else branch or cases for them.

Documentation

Full changelog: 1.0.0...1.1.0

License

Apache 2.0.