Skip to content

fix(android): enforce and publish certificate transparency - #92

Merged
yschimke merged 1 commit into
mainfrom
agent/fix-android-ct-results
Aug 29, 2026
Merged

fix(android): enforce and publish certificate transparency#92
yschimke merged 1 commit into
mainfrom
agent/fix-android-ct-results

Conversation

@yschimke

Copy link
Copy Markdown
Owner

Summary

  • route the deterministic CT fixture through Android platform trust policy with an application trust anchor
  • verify enforced and opted-out behavior on API 37 and publish the observation to the TLS policy table
  • preserve Android CT and ECH JSON through platform test storage instead of pulling an already-uninstalled test APK
  • keep the emulator runner on current v2.38.0; the shared Renovate config already groups GitHub Actions updates

Verification

  • Android compile, lint, public API, and fixture compilation checks
  • complete local ARM64 Android 17 / API 37 run: CT 2/2 and controlled ECH 3/3 passing
  • valid CT and ECH JSON artifacts parsed locally; site collector found the nested Android TLS policy report
  • public ECH probes remain non-gating; defo.ie currently reports its externally expired certificate

@yschimke
yschimke merged commit d7381af into main Aug 29, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant