How do I handle VAPT findings against the SDK?
Common VAPT findings on the SDK, and how to handle each
Common VAPT findings on the SDK, and how to handle each:
Hardcoded secrets: usually the API key / dev ID passed during init from your own code. Keep the API key on your backend, not in the client.
allowBackup=truein the SDK module: override it by settingandroid:allowBackup=falsewithtools:replacein your app manifest.Flagged cipher modes: these belong to a deprecated, inactive feature.
V2/V3 certificate signing: controlled by your app's
signingConfigs, not the SDK.
Last updated
Was this helpful?