mirror of
https://github.com/LawnchairLauncher/lawnchair.git
synced 2026-02-20 11:18:21 +00:00
1.2 KiB
1.2 KiB
Lawnchair verification
Lawnchair apk are cryptographically signed and can be verified using two verification systems
- GitHub or SLSA attestations
- SHA256 of android app certificate
SLSA Attestation
Note
It is possible to verify without GitHub CLI by cross-referencing check GitHub Attestation with Sigstore Rekor
Lawnchair repository is SLSA-Level 2 compliance
- Install GitHub CLI
- Download the APK and attestation from GitHub Attestation
- Run
gh attestation verify {APK} -R LawnchairLauncher/lawnchair, replace {APK} with the actual APK file - Done
Android App Certificate
Lawnchair have two app certificates, usually:
- Google Play:
47:AC:92:63:1C:60:35:13:CC:8D:26:DD:9C:FF:E0:71:9A:8B:36:55:44:DC:CE:C2:09:58:24:EC:25:61:20:A7 - Elsewhere:
74:7C:36:45:B3:57:25:8B:2E:23:E8:51:E5:3C:96:74:7F:E0:AD:D0:07:E5:BA:2C:D9:7E:8C:85:57:2E:4D:C5
Using a verification app like AppVerifier can ease up the verifying process.