4 ms·
> Java apps are usually quite easy to decompile and check. Search for library versions in use, force upgrades on security vulnerabilities. You don't even need
by iggldiggl 1y ago
> Java apps are usually quite easy to decompile and check. Search for library versions in use, force upgrades on security vulnerabilities.
You don't even need to do that – for a while already, Google's toolchain has been adding dependency metadata to all apps by default (encrypted, though, so only Google can read it) and they've indeed been using that to warn about outdated or vulnerable dependencies. According to https://support.google.com/googleplay/android-developer/answer/10358880 https://support.google.com/googleplay/android-developer/answ..., at most they'll only block you from releasing further updates including dependencies with critical vulnerabilities, though…