-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
📱 demo appUpdate of the Demo AppUpdate of the Demo App🔍 triageA new issue that needs to be treatedA new issue that needs to be treated🚨 securitySecurity-related topics (MobSF reports, CVE, Renovate, GitLeaks, etc.)Security-related topics (MobSF reports, CVE, Renovate, GitLeaks, etc.)
Description
Context
The IPA for the Design System Toolbox app (version 0.16.0) has been uploaded and is available through the App Store.
Our internal stores management service uses MobSF to make security audits on the app.
This service shares the report attached, with a score of 64/100 and some elements to check.
Definition of Done
- IPA BINARY CODE ANALYSIS n°1 (use of fopen, memcpy, sscanf). Not used directly in the app by our code, but maybe by Apple API or third-parties
- IPA BINARY CODE ANALYSIS n°2 (use of malloc). Not used directly in the app by our code, but maybe by Apple API or third-parties
- IPA BINARY ANALYSIS RPATH: check use of
@rpath
and remove if possible - IPA BINARY ANALYSIS ENCRYPTED: encypher the binary
Resources
Metadata
Metadata
Assignees
Labels
📱 demo appUpdate of the Demo AppUpdate of the Demo App🔍 triageA new issue that needs to be treatedA new issue that needs to be treated🚨 securitySecurity-related topics (MobSF reports, CVE, Renovate, GitLeaks, etc.)Security-related topics (MobSF reports, CVE, Renovate, GitLeaks, etc.)
Type
Projects
Status
Triage