| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
The APKFetch project team takes security and credential privacy seriously.
If you discover a potential security vulnerability in APKFetch:
- Do NOT open a public issue on GitHub.
- Email security vulnerability reports directly to
security@apkfetch.dev. - Provide detailed steps to reproduce the issue, environment information, and any potential proof of concept.
- Credential Storage: Google credentials and authentication sub-tokens are always stored using authenticated AES-256-GCM encryption with machine-derived key entropy and restricted file permissions (0600 on Unix, restricted user ACL on Windows).
- No Password Interception: APKFetch uses standard OAuth 2.0 with PKCE and never prompts for user passwords in the terminal.
- Strict Path Validation: All downloaded files are sanitized to eliminate any path traversal attack surfaces.