Skip to content

feat: appmeta v1 — APK and IPA metadata parser, CLI and release workflow - #1

Merged
gmegidish merged 17 commits into
mainfrom
feat/v1
Sep 29, 2026
Merged

gmegidish merged 17 commits into
mainfrom
feat/v1

Conversation

@gmegidish

Copy link
Copy Markdown
Member

Summary

First version of appmeta: a Go library and CLI that extract metadata from Android .apk and iOS .ipa files.

  • Library: Parse / ParseContext read through an io.ReaderAt, touching only the zip central directory and the entries they need. Input is treated as hostile: every read is bounded by Limits, and panics become errors.
  • APK: binary manifest, resources.arsc lookups for label and icon, adaptive icon foreground, native ABIs, debug vs release signing (v1, v2, v3, v3.1).
  • IPA: Info.plist (binary and XML), CgBI icons, Mach-O architectures and simulator detection, provisioning profile.
  • CLI: appmeta <app.apk|app.ipa> prints JSON matching schema/appmeta.schema.json.
  • Hardening (last code commit): read failures and cancelled contexts fail the parse instead of becoming warnings; MaxEntries is checked against the entries actually read; the APK signing block counts towards MaxTotalSize; permission deduplication is linear; brackets inside XML plist strings are not counted as nesting. Adds ErrMalformed and constants for format, platform and signing values.
  • CI: lint, test, vulncheck and fuzz run on every branch push and on pull requests. A vMAJOR.MINOR.PATCH tag creates a GitHub release with notes taken from CHANGELOG.md.

Notes for the reviewer

  • The release job uses the default GITHUB_TOKEN with contents: write.
  • Same-repo PR branches run CI twice (push and pull_request); pull_request is kept so fork PRs are checked.
  • go.mod declares go 1.26.0, and cobra lives in the library's module. Both affect importers and are not changed here.

Test plan

  • go vet ./...
  • go test -race -cover ./... — 85.6% library, 59.4% CLI
  • 15s local fuzz of FuzzParse, FuzzPlist, FuzzAPKSigning
  • golangci-lint (not installed locally; runs in CI)
  • CI green on this PR
  • After merge: tag v1.0.0 and confirm the release is created with the changelog notes

Read failures and cancelled contexts now fail the parse instead of
becoming warnings. MaxEntries is checked against the entries actually
read, the zip64 lookup honours the directory size marker, and the APK
signing block counts towards MaxTotalSize. Permission deduplication is
linear, and brackets inside XML plist strings no longer count as nesting.

Adds ErrMalformed and constants for the format, platform and signing
values. The CLI reports a failed write of its output.
A vMAJOR.MINOR.PATCH tag creates a GitHub release whose notes are the
matching section of CHANGELOG.md.
@gmegidish
gmegidish merged commit c986787 into main Sep 29, 2026
22 checks passed
@gmegidish
gmegidish deleted the feat/v1 branch September 29, 2026 09:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant