New app: Vector (io.vectorapp)
Vector is a private messenger and community client using Nostr Protocol. MIT, Rust + Tauri, everything builds from source. Listing text, screenshots and changelogs are in the repo under fastlane/metadata.
CI Note: my GitLab account is new and pipelines on my fork are blocked pending identity verification, which your template says not to do. Could a maintainer trigger the pipeline here? Our own CI runs the same recipe and scanner green on the pinned commit.
A few things worth knowing before you read the recipe:
The APK comes from a Cargo feature called fdroid. It removes the in-app updater by removing it at compilation, so the update-check and APK-download code isn't in this build at all (see src-tauri/src/commands/updates.rs). The regular GitHub builds do carry an updater for sideloaders; this one doesn't.
scripts/fdroid-build.sh is the whole recipe. prebuild and build call its two stages. It installs the pinned Rust toolchain, builds tauri-cli from crates.io, bundles our Svelte bits with rollup instead of esbuild, and deletes every native npm package after npm ci. If a .node or .wasm file is left over it refuses to continue. OpenSSL is compiled from source through openssl-src.
Reproducible builds: yes please! Binaries points at Vector-fdroid.apk on each GitHub release, built by the same script on a clean runner and signed with our release key; AllowedAPKSigningKeys is that certificate. If your rebuild doesn't match we'll chase the diff, as this is our first attempt at 100% reproducible builds for a platform.
The APK is arm64 only and around 65 MB: Tor (arti), whisper.cpp and Iroh are compiled in as native code. No model weights are bundled; Whisper models are only downloaded if a user asks for transcription and is explicitly opt-in. We're not doing per-ABI splits for now: 32-bit ARM demand is near zero and one versionCode per version keeps store and sideload installs interchangeable.
Vector runs WebXDC mini apps and is visible on WebXDC.org, the same model as Delta Chat: sandboxed web bundles a user chooses to add, nothing is fetched or executed on its own.
No anti-features that I know of.
Required
- The app complies with the inclusion criteria
- The original app author has been notified (and does not oppose the inclusion) (I am the author)
- All related fdroiddata and RFP issues have been referenced in this merge request (none exist)
- Builds with
fdroid buildand all pipelines pass (see note above) - There is an issue tracker and contact info of the author so that we can report bugs and contact the author.
Strongly Recommended
- The upstream app source code repo contains the app metadata (summary/description/images/changelog/etc) in a Fastlane or Triple-T folder structure
- Releases are tagged and auto update is enabled
Suggested
- External repos are added as git submodules instead of srclibs (none used)
- Enable Reproducible Builds
- Multiple apks for native code (arm64 only, see above)