{
  "schema": 1,
  "generated_at": "2026-09-04T08:55:10Z",
  "plain_language_summary": "Security scanners reduce risk; they cannot prove that software is harmless. VGNA publishes exact hashes, signing identities, scanner scope, findings, permissions, and data use so players can verify the claims themselves.",
  "artifacts": [
    {
      "id": "ios-current",
      "name": "VGNA Client for iPhone and iPad",
      "platform": "iOS / iPadOS",
      "version": "1.10",
      "release_label": "1.05",
      "build": "128",
      "download_url": "https://client.vgna.net/Vainglory.ipa",
      "bytes": 1729739038,
      "sha256": "9d8b253b21f875be1663e2e9c4650e642b2b35f9cab32cd24eb86ffdae98db13",
      "sha512": "eefdef00f413656d2cc9f5f6f16c199136b99375a97090db00da10e2da36c1dcd80471314734ad94cd079812c0d9eb5901018aad4b803e85083e485887eb2f30",
      "package_id": "com.richardtravel.vgnaclient",
      "signing": {
        "status": "verified_from_embedded_provisioning_profile",
        "identity": "Apple Distribution: Mark Richard (ZM2322XZSJ)",
        "certificate_sha256": "cc5f7e7cd4c986555c7c133438c284ead75fda82cf2208391c750e79fa8be99e",
        "certificate_expires": "2027-07-16T21:03:27Z"
      },
      "scans": {
        "virustotal_url": {
          "status": "completed",
          "malicious": 0,
          "suspicious": 0,
          "total": 91,
          "analysis_at": "2026-09-04T08:19:26Z",
          "scope": "download_url",
          "source_url": "https://client.vgna.net/Vainglory.ipa",
          "report_url": "https://www.virustotal.com/gui/url/91ca8f453be0bfa997907a5f148d1c2bace8a499ff541bf2aee8443c4570f5fc/detection"
        },
        "virustotal_file": {
          "status": "not_eligible",
          "scope": "exact_file",
          "source_sha256": "9d8b253b21f875be1663e2e9c4650e642b2b35f9cab32cd24eb86ffdae98db13",
          "reason": "Artifact exceeds VirusTotal's 650 MB API upload limit."
        },
        "clamav": {
          "status": "completed",
          "scope": "exact_file",
          "engine": "ClamAV 1.5.3/28078/Fri Jul 31 06:24:10 2026",
          "findings": [
            "Heuristics.Limits.Exceeded.MaxScanTime FOUND"
          ],
          "detected": true,
          "analysis_at": "2026-09-04T08:50:09Z",
          "source_sha256": "9d8b253b21f875be1663e2e9c4650e642b2b35f9cab32cd24eb86ffdae98db13"
        }
      }
    },
    {
      "id": "android-oem-current",
      "name": "Android \u2014 Replace Original Vainglory",
      "platform": "Android",
      "version": "1.09",
      "release_label": "1.09",
      "download_url": "https://client.vgna.net/android/VGNA-Client-Android-1.09-OEM.apk",
      "bytes": 90771063,
      "sha256": "467131a7496f6d1e78f8d162b7c35219a62425bff7ddc4ed586030cfec755d60",
      "sha512": "494e86700344e3b159ff21e2eb0a78aab249277cc2702a8f28caf9b2fde0f82f08c9dcb4ec28410d04ae0a5a1477ad3172baa0956e05853b21d41c4285830e8e",
      "package_id": "com.superevilmegacorp.game",
      "analysis_context": "This modified Community Edition package inherits Vainglory's 2019 Android minimum-SDK setting, legacy code patterns, and stock third-party libraries. MobSF publishes those findings unsuppressed. VGNA did not add an advertising or behavioral-analytics SDK.",
      "signing": {
        "status": "verified",
        "identity": "VGNA Client",
        "certificate_sha256": "28358dab239dd992b11fc0da510e774f56e70428f50ce519e12c5aabfc038c40",
        "certificate_expires": "2053-12-05T04:03:17Z"
      },
      "scan_policy": {
        "expected_repackaging_classification": true
      },
      "scans": {
        "virustotal_url": {
          "status": "completed",
          "malicious": 0,
          "suspicious": 0,
          "total": 92,
          "analysis_at": "2026-08-30T23:28:52Z",
          "scope": "download_url",
          "source_url": "https://client.vgna.net/android/VGNA-Client-Android-1.09-OEM.apk",
          "report_url": "https://www.virustotal.com/gui/url/40889c3b9f3ed4d45901bbdec89553529ae980def166e38ed725b02cf10ec727/detection"
        },
        "virustotal_file": {
          "status": "completed",
          "malicious": 0,
          "suspicious": 0,
          "total": 75,
          "analysis_at": "2026-08-30T23:29:17Z",
          "scope": "exact_file",
          "source_sha256": "467131a7496f6d1e78f8d162b7c35219a62425bff7ddc4ed586030cfec755d60",
          "report_url": "https://www.virustotal.com/gui/file/467131a7496f6d1e78f8d162b7c35219a62425bff7ddc4ed586030cfec755d60/detection"
        },
        "clamav": {
          "status": "completed",
          "scope": "exact_file",
          "engine": "ClamAV 1.5.3/28078/Fri Jul 31 06:24:10 2026",
          "findings": [],
          "detected": false,
          "analysis_at": "2026-08-30T23:32:32Z",
          "source_sha256": "467131a7496f6d1e78f8d162b7c35219a62425bff7ddc4ed586030cfec755d60"
        }
      },
      "analysis": {
        "mobsf_static": {
          "status": "completed",
          "scope": "exact_file",
          "provider": "MobSF",
          "provider_version": "4.5.1",
          "source_sha256": "467131a7496f6d1e78f8d162b7c35219a62425bff7ddc4ed586030cfec755d60",
          "security_score": 49,
          "severity_counts": {
            "high": 3,
            "warning": 21,
            "hotspot": 2,
            "secure": 2,
            "info": 2
          },
          "analysis_at": "2026-09-04T08:53:22Z",
          "report_url": "reports/android-oem-current.mobsf-summary.json",
          "explanation": "Private, resource-limited MobSF static analysis. Counts are security review observations, not malware-engine detections. This modified Community Edition package inherits Vainglory's 2019 Android minimum-SDK setting, legacy code patterns, and stock third-party libraries. MobSF publishes those findings unsuppressed. VGNA did not add an advertising or behavioral-analytics SDK."
        },
        "sbom": {
          "status": "completed",
          "scope": "exact_file",
          "format": "SPDX JSON",
          "generator": "syft 1.50.0",
          "source_sha256": "467131a7496f6d1e78f8d162b7c35219a62425bff7ddc4ed586030cfec755d60",
          "package_count": 1,
          "file_count": 0,
          "analysis_at": "2026-09-04T08:55:02Z",
          "report_url": "reports/android-oem-current.spdx.json",
          "explanation": "Machine-readable inventory; coverage depends on identifiable packaged components."
        },
        "known_vulnerabilities": {
          "status": "completed",
          "scope": "sbom",
          "provider": "Grype",
          "provider_version": "grype 0.116.1",
          "source_sha256": "467131a7496f6d1e78f8d162b7c35219a62425bff7ddc4ed586030cfec755d60",
          "severity_counts": {
            "Critical": 0,
            "High": 0,
            "Medium": 0,
            "Low": 0,
            "Negligible": 0,
            "Unknown": 0
          },
          "analysis_at": "2026-09-04T08:55:02Z",
          "report_url": "reports/android-oem-current.grype.json",
          "explanation": "Known-vulnerability matches in the generated SBOM; this is not a malware scan."
        }
      }
    },
    {
      "id": "android-side-by-side-current",
      "name": "Android \u2014 Install Alongside Vainglory",
      "platform": "Android",
      "version": "1.09",
      "release_label": "1.09",
      "download_url": "https://client.vgna.net/android/VGNA-Client-Android-1.09-Side-by-Side.apk",
      "bytes": 90771063,
      "sha256": "a5fd1f1f79ea5cfb5875d08e9d0722251e301f92d78a93e2aa6a4d5c0fca6a71",
      "sha512": "2a507f54091f9238c2ec1b87dc8301510376e9b66eb7c6243718687af89369363858953d880781a2ca9b4f82ed6cca9b299e29765176c7c70f34d42d149c4e65",
      "package_id": "net.vgna.client",
      "analysis_context": "This modified Community Edition package inherits Vainglory's 2019 Android minimum-SDK setting, legacy code patterns, and stock third-party libraries. MobSF publishes those findings unsuppressed. VGNA did not add an advertising or behavioral-analytics SDK.",
      "signing": {
        "status": "verified",
        "identity": "VGNA Client",
        "certificate_sha256": "28358dab239dd992b11fc0da510e774f56e70428f50ce519e12c5aabfc038c40",
        "certificate_expires": "2053-12-05T04:03:17Z"
      },
      "scan_policy": {
        "virustotal_file": false,
        "reason": "VirusTotal exact-file submission is performed for the OEM APK built from the same release source. This exact side-by-side APK still receives ClamAV, MobSF, SBOM, and Grype analysis."
      },
      "scans": {
        "virustotal_url": {
          "status": "completed",
          "malicious": 0,
          "suspicious": 0,
          "total": 92,
          "analysis_at": "2026-08-30T23:32:33Z",
          "scope": "download_url",
          "source_url": "https://client.vgna.net/android/VGNA-Client-Android-1.09-Side-by-Side.apk",
          "report_url": "https://www.virustotal.com/gui/url/88eff7c7da6ff471d93306a9aa981f6542c14e070621c4656de801c4a131ded2/detection"
        },
        "clamav": {
          "status": "completed",
          "scope": "exact_file",
          "engine": "ClamAV 1.5.3/28078/Fri Jul 31 06:24:10 2026",
          "findings": [],
          "detected": false,
          "analysis_at": "2026-08-30T23:34:33Z",
          "source_sha256": "a5fd1f1f79ea5cfb5875d08e9d0722251e301f92d78a93e2aa6a4d5c0fca6a71"
        }
      },
      "analysis": {
        "mobsf_static": {
          "status": "completed",
          "scope": "exact_file",
          "provider": "MobSF",
          "provider_version": "4.5.1",
          "source_sha256": "a5fd1f1f79ea5cfb5875d08e9d0722251e301f92d78a93e2aa6a4d5c0fca6a71",
          "security_score": 49,
          "severity_counts": {
            "high": 3,
            "warning": 21,
            "hotspot": 2,
            "secure": 2,
            "info": 2
          },
          "analysis_at": "2026-09-04T08:53:24Z",
          "report_url": "reports/android-side-by-side-current.mobsf-summary.json",
          "explanation": "Private, resource-limited MobSF static analysis. Counts are security review observations, not malware-engine detections. This modified Community Edition package inherits Vainglory's 2019 Android minimum-SDK setting, legacy code patterns, and stock third-party libraries. MobSF publishes those findings unsuppressed. VGNA did not add an advertising or behavioral-analytics SDK."
        },
        "sbom": {
          "status": "completed",
          "scope": "exact_file",
          "format": "SPDX JSON",
          "generator": "syft 1.50.0",
          "source_sha256": "a5fd1f1f79ea5cfb5875d08e9d0722251e301f92d78a93e2aa6a4d5c0fca6a71",
          "package_count": 1,
          "file_count": 0,
          "analysis_at": "2026-09-04T08:55:07Z",
          "report_url": "reports/android-side-by-side-current.spdx.json",
          "explanation": "Machine-readable inventory; coverage depends on identifiable packaged components."
        },
        "known_vulnerabilities": {
          "status": "completed",
          "scope": "sbom",
          "provider": "Grype",
          "provider_version": "grype 0.116.1",
          "source_sha256": "a5fd1f1f79ea5cfb5875d08e9d0722251e301f92d78a93e2aa6a4d5c0fca6a71",
          "severity_counts": {
            "Critical": 0,
            "High": 0,
            "Medium": 0,
            "Low": 0,
            "Negligible": 0,
            "Unknown": 0
          },
          "analysis_at": "2026-09-04T08:55:07Z",
          "report_url": "reports/android-side-by-side-current.grype.json",
          "explanation": "Known-vulnerability matches in the generated SBOM; this is not a malware scan."
        }
      }
    }
  ],
  "components": [
    {
      "id": "ios-vgna-framework-current",
      "name": "Exact VGNAFeatures framework executable extracted from the signed iOS 1.09 IPA",
      "role": "This framework executable is the VGNA-controlled modification layer in the modern Xcode container. It adds VGNA integration, replay handling, and related client behavior without relying on a loose dynamic library.",
      "base_game": "Underneath this framework is the standard Vainglory Community Edition client. VGNA publishes the exact executable separately so players can distinguish the VGNA-added code from the underlying CE game.",
      "analysis_context": "This result covers only the exact VGNAFeatures framework executable, not the underlying Community Edition app bundle or stock game assets.",
      "parent_artifact_id": "ios-current",
      "archive_path": "Payload/VGNAClient.app/Frameworks/VGNAFeatures.framework/VGNAFeatures",
      "download_url": "https://client.vgna.net/trust/artifacts/VGNAFeatures",
      "bytes": 724656,
      "sha256": "cbb4ea37ff42d8461bae55a0fcff6a28eff5850a4ae096877ba0b82112e867b3",
      "sha512": "f0c21f1ac39e87c8bbca12d4280765c4cb6d863816d981a736684697dfd8d3948fadefa9a20b1793b9e07d183a3384d2c5b212825519e0a68556f39e11c24d75",
      "scans": {
        "virustotal_file": {
          "status": "completed",
          "malicious": 0,
          "suspicious": 0,
          "total": 75,
          "analysis_at": "2026-09-04T08:50:12Z",
          "scope": "exact_component",
          "source_sha256": "cbb4ea37ff42d8461bae55a0fcff6a28eff5850a4ae096877ba0b82112e867b3",
          "report_url": "https://www.virustotal.com/gui/file/cbb4ea37ff42d8461bae55a0fcff6a28eff5850a4ae096877ba0b82112e867b3/detection"
        },
        "clamav": {
          "status": "completed",
          "scope": "exact_component",
          "engine": "ClamAV 1.5.3/28078/Fri Jul 31 06:24:10 2026",
          "findings": [],
          "detected": false,
          "analysis_at": "2026-09-04T08:52:38Z",
          "source_sha256": "cbb4ea37ff42d8461bae55a0fcff6a28eff5850a4ae096877ba0b82112e867b3"
        }
      },
      "analysis": {
        "mobsf_static": {
          "status": "completed",
          "scope": "exact_component",
          "provider": "MobSF",
          "provider_version": "4.5.1",
          "source_sha256": "cbb4ea37ff42d8461bae55a0fcff6a28eff5850a4ae096877ba0b82112e867b3",
          "security_score": 73,
          "severity_counts": {
            "high": 0,
            "warning": 2,
            "hotspot": 0,
            "secure": 1,
            "info": 1
          },
          "analysis_at": "2026-09-04T08:53:28Z",
          "report_url": "reports/ios-vgna-framework-current.mobsf-summary.json",
          "explanation": "Private, resource-limited MobSF static analysis. Counts are security review observations, not malware-engine detections. This result covers only the exact VGNAFeatures framework executable, not the underlying Community Edition app bundle or stock game assets."
        },
        "sbom": {
          "status": "completed",
          "scope": "exact_component",
          "format": "SPDX JSON",
          "generator": "syft 1.50.0",
          "source_sha256": "cbb4ea37ff42d8461bae55a0fcff6a28eff5850a4ae096877ba0b82112e867b3",
          "package_count": 1,
          "file_count": 1,
          "analysis_at": "2026-09-04T08:55:10Z",
          "report_url": "reports/ios-vgna-framework-current.spdx.json",
          "explanation": "Machine-readable inventory; coverage depends on identifiable packaged components."
        },
        "known_vulnerabilities": {
          "status": "completed",
          "scope": "component_sbom",
          "provider": "Grype",
          "provider_version": "grype 0.116.1",
          "source_sha256": "cbb4ea37ff42d8461bae55a0fcff6a28eff5850a4ae096877ba0b82112e867b3",
          "severity_counts": {
            "Critical": 0,
            "High": 0,
            "Medium": 0,
            "Low": 0,
            "Negligible": 0,
            "Unknown": 0
          },
          "analysis_at": "2026-09-04T08:55:10Z",
          "report_url": "reports/ios-vgna-framework-current.grype.json",
          "explanation": "Known-vulnerability matches in the generated SBOM; this is not a malware scan."
        }
      }
    }
  ],
  "provider_notes": {
    "virustotal": "Public URL reports and exact-file reports are separate evidence. A URL result does not mean every byte was scanned. The current VirusTotal browser form was tested from the VPS with the exact IPA and displayed its 650 MB maximum-file-size rejection.",
    "clamav": "ClamAV scans are performed locally with the current official signature database. Results are published with engine/database version but do not have an independent public report URL.",
    "mobsf": "MobSF is a private, self-hosted static-analysis tool, not an independent antivirus laboratory. VGNA publishes exact-hash summaries and all finding titles without publishing extracted strings, source snippets, URLs, or possible secret values.",
    "grype": "A zero-match Grype result means no known vulnerability match was found in the packages Syft could identify. It does not cover unidentified proprietary code and is not a malware verdict.",
    "malwarebytes": "Malwarebytes/ThreatDown currently exposes an enterprise endpoint-management API, not a public arbitrary-file upload API. No Malwarebytes-clean claim is published. If VGNA obtains a licensed managed scanning endpoint, that endpoint result will be labeled separately and will not be presented as a public file report.",
    "sbom": "Component inventories cover identifiable packaged software. The proprietary original Vainglory base is not reproducibly buildable from VGNA source, so an SBOM cannot prove the contents or safety of every stock game asset."
  },
  "provenance": {
    "status": "completed",
    "signature_algorithm": "Ed25519",
    "manifest_url": "reports/release-manifest.json",
    "signature_url": "reports/release-manifest.sig",
    "public_key_url": "reports/vgna-release-attestation-public.pem",
    "public_key_sha256": "740f3da8714286701e0f6d4eabb7894af19b214c606bcfb50e6fc97e6b8c43ee",
    "explanation": "The VGNA release server signs a manifest that binds every published artifact and report to its exact hash. This is publisher provenance, not an independent safety verdict."
  }
}
