You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on May 20, 2025. It is now read-only.
For security reasons, how does CodePush authenticate the app that it's sending the bundle to? That is, does any app with the key receive the pushed js bundle? If so, it will pose a security risk as the key is stored in plaintext and can be leaked at the client app side.
Additionally, I am also curious where CodePush stores the downloaded js bundle. When I checked the app folder in Android, I wasn't able to find any downloaded bundle there. Reason to ask this question is whether the downloaded bundle is securely stored.