Skip to content

Security: AIwolfie/ApkFetch

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
1.0.x ✅
< 1.0 ❌

Reporting a Vulnerability

The APKFetch project team takes security and credential privacy seriously.

If you discover a potential security vulnerability in APKFetch:

  1. Do NOT open a public issue on GitHub.
  2. Email security vulnerability reports directly to security@apkfetch.dev.
  3. Provide detailed steps to reproduce the issue, environment information, and any potential proof of concept.

Security Guarantees

  • Credential Storage: Google credentials and authentication sub-tokens are always stored using authenticated AES-256-GCM encryption with machine-derived key entropy and restricted file permissions (0600 on Unix, restricted user ACL on Windows).
  • No Password Interception: APKFetch uses standard OAuth 2.0 with PKCE and never prompts for user passwords in the terminal.
  • Strict Path Validation: All downloaded files are sanitized to eliminate any path traversal attack surfaces.

There aren't any published security advisories