
JShelby233745 (Community Member) asked a question.
The scan is reporting "Improper Export of Android Application Components" for the startup Activities in our apps. We are following the standard approach for configuring the Activity for the Launcher ("android.intent.category.LAUNCHER") and the app won't start if we set app specific permissions. Is there something else we should be doing?
.png)
Hi @JShelby233745 (Community Member) ,
Thank you for your patience. I've contacted Veracode Research and was able to confirm that unfortunately at this time we do not automatically exempt activities with the Launcher category from being reported on for this category though as you mentioned there is no need to restrict this activity.
Please propose a "Potential False Positive" mitigation on this in the Veracode Platform or through our IDE integrations, you can find more information on how to do this here: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/~p4MSKOS8F8X8h0KwFTKoQ . I would recommend adding a link to this community posting in the mitigation proposal.
Afterwards, please contact your security team for approval for this proposal.
Please let me know if you have any remaining questions or concerns.
Thank you,
Boy Baukema