List APK signing certificate fingerprint so users can verify releases
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 72/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Active
- Domain
- documentation, mobile, security
Research direction
Start by locating the published APK in the Releases page and inspect its signing certificate with keytool or an equivalent Android tool. Add the SHA-256 fingerprint, with SHA-1 if available, to the README or release information. Done means users can compare the published fingerprint with the APK they installed.
Written by the indexing model from the issue text.
Description
Use case
I'm installing this app via Obtanium / sideloading, and I'd like to make sure the APK I install is genuinely signed by you (and not a tampered or repackaged build).
To verify this, I use a certificate-fingerprint check (e.g., AppVerifier, or keytool -printcert -jarfile app.apk on desktop). For that to work, I need the signing certificate's fingerprint published somewhere I can compare against.
Proposed solution
Please add the SHA-256 fingerprint of the signing certificate (SHA-1 is a fine bonus) to the README and/or the Releases page, e.g.:
- Dominant language
- Kotlin
- Stars
- 29.9k
- Forks
- 1.7k
- PR merge metrics
- No merged PRs in 30d
Getting set up
We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from librepods-org/librepods
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
librepods-org/librepods#771 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
librepods-org/librepods#770 ·
Maintainers usually reply within 1 day
-
android
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
librepods-org/librepods#756 · 1 comment · 2 reactions ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
librepods-org/librepods#738 ·
Maintainers usually reply within 1 day
-
Proposal: cross-link as complementary projects (OpenHearing — hearing test + assist for any earbuds)Open
Difficulty 1/5 Under an hour Newbie friendliness 68/100
librepods-org/librepods#660 · 1 reaction ·
Maintainers usually reply within 1 day
All issues in librepods-org/librepods
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
block/artifact-swap#176 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
mrmans0n/asyncresult#102 ·
Maintainers usually reply within 2 days
-
follow-up
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
yschimke/homeassistant-remotecompose#680 ·
Maintainers usually reply within 1 day
-
:wave: team-triage a:chore in:isolated-projects in:kotlin-dsl
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
task
Difficulty 2/5 1-3 hours Newbie friendliness 72/100