Skip to content

Commit 54ae8d7

Browse files
release: freeRASP 9.1.0 (Android SDK 19.2.1, iOS SDK 7.1.2) (#71)
* release: freeRASP 9.1.0 (Android SDK 19.2.1) Bump TalsecSecurity-Community-Cordova to 19.2.1 and migrate the Android bridge to the SDK's new package and callback names. 19.2.1 moves the SDK from com.aheaditec.talsec_security.security.api to app.talsec.rasp.security.api and renames every ThreatListener callback to match its threat name (onRootDetected -> onPrivilegedAccess, onADBEnabledDetected -> onAdbEnabled, and so on). Expose the release's new onBootloader() callback as the Android-only `bootloader` threat. The native ALL_EVENTS list and the TypeScript Android getValues() branch are matched by position, so Bootloader is appended to both; the iOS list is unchanged. Resolve the SDK's JitPack dependencies from the Talsec common registry instead of jitpack.io. Co-authored-by: Cursor <cursoragent@cursor.com> * release: iOS SDK 7.1.2 Update TalsecRuntime.xcframework from 6.14.4 to 7.1.2. Changelog covers 6.14.5, 7.1.0 and 7.1.2 since the repo was three releases behind. Public Swift API change is additive, so the plugin bridge is unchanged. * ci: pin a generic simulator destination for the iOS build cordova-ios derives the xcodebuild destination as 'platform=iOS Simulator,name=<device>' with no OS component, so xcodebuild resolves OS:latest. The macOS runner image now carries several iOS runtimes and the device cordova picks does not exist on the newest one, so the build failed with 'Unable to find a device matching the provided destination specifier'. This job only compiles, so a generic simulator destination avoids depending on which devices the runner image happens to create. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>
1 parent cb27dfe commit 54ae8d7

54 files changed

Lines changed: 1686 additions & 1023 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/ci.yml‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -146,4 +146,7 @@ jobs:
146146

147147
- name: Build iOS
148148
working-directory: ./example
149-
run: ionic cordova build ios --confirm
149+
# cordova-ios picks a simulator by name but omits the OS, so xcodebuild
150+
# resolves OS:latest and fails when that device only exists on an older
151+
# runtime. A generic destination is enough since this job only builds.
152+
run: ionic cordova build ios --emulator --confirm -- --buildFlag="-destination generic/platform=iOS Simulator"

‎CHANGELOG.md‎

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,51 @@ All notable changes to this project will be documented in this file.
55
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
66
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
77

8+
## [9.1.0] - 2026-08-07
9+
10+
- Android SDK version: 19.2.1
11+
- iOS SDK version: 7.1.2
12+
13+
### Cordova
14+
15+
#### Added
16+
17+
- `bootloader` threat callback, reporting an unlocked or compromised bootloader — Android only
18+
19+
### Android
20+
21+
#### Added
22+
23+
- Added bootloader detection (unlocked/compromised) with `onBootloader()` callback
24+
- Added option to fetch JitPack dependencies from our own Talsec repository (`https://europe-west3-maven.pkg.dev/talsec-artifact-repository/common`)
25+
26+
#### Fixed
27+
28+
- Fixed native crash caused by std::terminate() race condition
29+
- Fixed periodic hook and root check overwriting
30+
- Fixed root detection crash in obfuscated release builds
31+
- Fixed hardware-backed keystore detection failing with `NoSuchMethodError` on some Android 12+ devices
32+
33+
#### Changed
34+
35+
- Improved KernelSU detection
36+
- Improved hook detection
37+
- Improved Frida detection
38+
- Improved root detection capabilities
39+
40+
### iOS
41+
42+
#### Added
43+
44+
- Improved jailbreak detection
45+
- Added support for postponed checks, therefore, due to slower execution, some subchecks are run after initial startup checks.
46+
- Improved hook detection.
47+
48+
#### Fixed
49+
50+
- Fixed issue with app's color scheme initialization.
51+
- Fixed bad memory access in jaibreak check.
52+
853
## [9.0.0] - 2026-05-15
954

1055
- Android SDK version: 18.3.0

‎example/src/app/app.component.ts‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -182,6 +182,7 @@ export class AppComponent implements OnInit {
182182
locationSpoofing: () => this.updateAppChecks('Location Spoofing'),
183183
unsecureWifi: () => this.updateAppChecks('Unsecure Wi-Fi'),
184184
automation: () => this.updateAppChecks('Automation'),
185+
bootloader: () => this.updateAppChecks('Bootloader'),
185186
};
186187

187188
raspExecutionStateActions = {

‎example/src/app/utils/checks.ts‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,4 +25,5 @@ export const androidChecks = [
2525
{ name: 'Location Spoofing', isSecure: true },
2626
{ name: 'Unsecure Wi-Fi', isSecure: true },
2727
{ name: 'Automation', isSecure: true },
28+
{ name: 'Bootloader', isSecure: true },
2829
];

‎package-lock.json‎

Lines changed: 2 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"name": "cordova-talsec-plugin-freerasp",
3-
"version": "9.0.0",
3+
"version": "9.1.0",
44
"description": "Cordova plugin for improving app security and threat monitoring on Android and iOS mobile devices.",
55
"cordova": {
66
"id": "cordova-talsec-plugin-freerasp",

‎plugin.xml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
<plugin xmlns="http://apache.org/cordova/ns/plugins/1.0"
44
id="cordova-talsec-plugin-freerasp"
5-
version="9.0.0">
5+
version="9.1.0">
66

77
<name>freerasp</name>
88
<author>Talsec (info@talsec.app)</author>

‎src/android/ScreenProtector.kt‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ import android.util.Log
1010
import android.view.WindowManager.SCREEN_RECORDING_STATE_VISIBLE
1111
import androidx.annotation.RequiresApi
1212
import androidx.core.content.ContextCompat
13-
import com.aheaditec.talsec_security.security.api.Talsec
13+
import app.talsec.rasp.security.api.Talsec
1414
import java.util.function.Consumer
1515

1616
@RequiresApi(Build.VERSION_CODES.UPSIDE_DOWN_CAKE)

‎src/android/TalsecPlugin.kt‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,9 @@ import android.os.Handler
66
import android.os.HandlerThread
77
import android.os.Looper
88
import android.util.Log
9+
import app.talsec.rasp.security.api.SuspiciousAppInfo
10+
import app.talsec.rasp.security.api.Talsec
11+
import app.talsec.rasp.security.api.TalsecConfig
912
import com.aheaditec.talsec.cordova.dispatchers.ExecutionStateDispatcher
1013
import com.aheaditec.talsec.cordova.dispatchers.ThreatDispatcher
1114
import com.aheaditec.talsec.cordova.events.BaseRaspEvent
@@ -20,9 +23,6 @@ import com.aheaditec.talsec.cordova.utils.getArraySafe
2023
import com.aheaditec.talsec.cordova.utils.getBooleanSafe
2124
import com.aheaditec.talsec.cordova.utils.getStringSafe
2225
import com.aheaditec.talsec.cordova.utils.toSuspiciousAppDetectionConfig
23-
import com.aheaditec.talsec_security.security.api.SuspiciousAppInfo
24-
import com.aheaditec.talsec_security.security.api.Talsec
25-
import com.aheaditec.talsec_security.security.api.TalsecConfig
2626

2727
import org.apache.cordova.CallbackContext
2828
import org.apache.cordova.CordovaPlugin

‎src/android/TalsecThreatHandler.kt‎

Lines changed: 27 additions & 23 deletions
Original file line numberDiff line numberDiff line change
@@ -1,99 +1,103 @@
11
package com.aheaditec.talsec.cordova
22

33
import android.content.Context
4+
import app.talsec.rasp.security.api.SuspiciousAppInfo
5+
import app.talsec.rasp.security.api.ThreatListener
46
import com.aheaditec.talsec.cordova.dispatchers.ExecutionStateDispatcher
57
import com.aheaditec.talsec.cordova.dispatchers.ThreatDispatcher
68
import com.aheaditec.talsec.cordova.events.RaspExecutionStateEvent
79
import com.aheaditec.talsec.cordova.events.ThreatEvent
8-
import com.aheaditec.talsec_security.security.api.SuspiciousAppInfo
9-
import com.aheaditec.talsec_security.security.api.ThreatListener
1010

1111
internal object TalsecThreatHandler {
1212

1313
private val threatDetected = object : ThreatListener.ThreatDetected() {
14-
override fun onRootDetected() {
14+
override fun onPrivilegedAccess() {
1515
ThreatDispatcher.dispatchThreat(ThreatEvent.PrivilegedAccess)
1616
}
1717

18-
override fun onDebuggerDetected() {
18+
override fun onDebug() {
1919
ThreatDispatcher.dispatchThreat(ThreatEvent.Debug)
2020
}
2121

22-
override fun onEmulatorDetected() {
22+
override fun onSimulator() {
2323
ThreatDispatcher.dispatchThreat(ThreatEvent.Simulator)
2424
}
2525

26-
override fun onTamperDetected() {
26+
override fun onAppIntegrity() {
2727
ThreatDispatcher.dispatchThreat(ThreatEvent.AppIntegrity)
2828
}
2929

30-
override fun onUntrustedInstallationSourceDetected() {
30+
override fun onUnofficialStore() {
3131
ThreatDispatcher.dispatchThreat(ThreatEvent.UnofficialStore)
3232
}
3333

34-
override fun onHookDetected() {
34+
override fun onHooks() {
3535
ThreatDispatcher.dispatchThreat(ThreatEvent.Hooks)
3636
}
3737

38-
override fun onDeviceBindingDetected() {
38+
override fun onDeviceBinding() {
3939
ThreatDispatcher.dispatchThreat(ThreatEvent.DeviceBinding)
4040
}
4141

42-
override fun onObfuscationIssuesDetected() {
42+
override fun onObfuscationIssues() {
4343
ThreatDispatcher.dispatchThreat(ThreatEvent.ObfuscationIssues)
4444
}
4545

46-
override fun onMalwareDetected(suspiciousAppInfos: MutableList<SuspiciousAppInfo>) {
46+
override fun onMalware(suspiciousAppInfos: MutableList<SuspiciousAppInfo>) {
4747
ThreatDispatcher.dispatchMalware(suspiciousAppInfos)
4848
}
4949

50-
override fun onScreenshotDetected() {
50+
override fun onScreenshot() {
5151
ThreatDispatcher.dispatchThreat(ThreatEvent.Screenshot)
5252
}
5353

54-
override fun onScreenRecordingDetected() {
54+
override fun onScreenRecording() {
5555
ThreatDispatcher.dispatchThreat(ThreatEvent.ScreenRecording)
5656
}
5757

58-
override fun onMultiInstanceDetected() {
58+
override fun onMultiInstance() {
5959
ThreatDispatcher.dispatchThreat(ThreatEvent.MultiInstance)
6060
}
6161

62-
override fun onUnsecureWifiDetected() {
62+
override fun onUnsecureWifi() {
6363
ThreatDispatcher.dispatchThreat(ThreatEvent.UnsecureWifi)
6464
}
6565

66-
override fun onTimeSpoofingDetected() {
66+
override fun onTimeSpoofing() {
6767
ThreatDispatcher.dispatchThreat(ThreatEvent.TimeSpoofing)
6868
}
6969

70-
override fun onLocationSpoofingDetected() {
70+
override fun onLocationSpoofing() {
7171
ThreatDispatcher.dispatchThreat(ThreatEvent.LocationSpoofing)
7272
}
7373

74-
override fun onAutomationDetected() {
74+
override fun onAutomation() {
7575
ThreatDispatcher.dispatchThreat(ThreatEvent.Automation)
7676
}
77+
78+
override fun onBootloader() {
79+
ThreatDispatcher.dispatchThreat(ThreatEvent.Bootloader)
80+
}
7781
}
7882

7983
private val deviceState = object : ThreatListener.DeviceState() {
80-
override fun onUnlockedDeviceDetected() {
84+
override fun onPasscode() {
8185
ThreatDispatcher.dispatchThreat(ThreatEvent.Passcode)
8286
}
8387

84-
override fun onHardwareBackedKeystoreNotAvailableDetected() {
88+
override fun onSecureHardwareNotAvailable() {
8589
ThreatDispatcher.dispatchThreat(ThreatEvent.SecureHardwareNotAvailable)
8690
}
8791

88-
override fun onDeveloperModeDetected() {
92+
override fun onDevMode() {
8993
ThreatDispatcher.dispatchThreat(ThreatEvent.DevMode)
9094
}
9195

92-
override fun onADBEnabledDetected() {
96+
override fun onAdbEnabled() {
9397
ThreatDispatcher.dispatchThreat(ThreatEvent.ADBEnabled)
9498
}
9599

96-
override fun onSystemVPNDetected() {
100+
override fun onSystemVpn() {
97101
ThreatDispatcher.dispatchThreat(ThreatEvent.SystemVPN)
98102
}
99103
}

0 commit comments

Comments
 (0)