New app: Tern

Tern installs and updates apps from where their developers publish them (GitHub, GitLab, Codeberg, repos they run, plain download pages) and checks the signing certificate, checksum and version before anything installs. It runs on phones and Android TV.

No AntiFeatures: it only connects to sources the user adds. Obtainium, Droid-ify and Neo Store carry none either.

Reproducible build: Binaries and AllowedAPKSigningKeys point at the signed v0.1.0 release, and the repo's CI builds twice in separate folders and compares on every push. scandelete drops the test fixtures (signed test APKs and index jars).

Checklist

Policy

  • The app complies with the inclusion criteria.
  • The original app author has been notified (and does not oppose the inclusion). I'm the author.
  • The upstream app source code repo contains the app metadata in a Fastlane or Triple-T folder structure. The summary and description must be included and images, icon, and changelog should also be provided for better user experience. The en-US locale must be included.

Docs

Merge Request Setup

Metadata

  • Metadata must be put in metadata/<applicationId>.yml.
  • Metadata must be a valid YAML file.
  • Metadata must use LF as line ending.
  • Don't add summary/description/changelog/images or anything that should be provided in upstream repo. Please check the Changes tab to make sure there is no other unrelated files added in the MR.
  • Releases are tagged and auto update is enabled unless there is a special reason.
  • There is an issue tracker and contact info of the author so that we can report bugs and contact the author.
  • An AuthorName must be added. It doesn't need to be the real name.
  • External repos are added as git submodules instead of srclibs. You can update git submodules without opening an MR in this repo and the submodule is covered by our scanner.
  • Enable Reproducible Builds. We'll use your signature for improved security/reliability, also allowing users to switch between different channels. Do note that if you don't enable reproducible build then the apk will be signed with our key so you can't enable it later. If you can't enable this, please add the reasons here.
  • Setup abi split if the APK is large and the splitted ones can be much smaller. No native code, 5 MB.
  • Only the latest versions should be kept in the metadata before it's merged. If you update the metadata, please replace the old versions with the new ones.
  • Don't add any disabled versions in the metadata.
  • The commit field should be the full hash. Please don't use tag or branch in commit.

Pipeline

  • All pipelines should pass.
  • All warnings and errors in the Reports tab should be fixed or explained.
  • F-Droid CI runners are under GitLab's FOSS program, so there's no need for you to pay for any CI time. If Gitlab starts asking for phone numbers or credit cards don't submit anything, just leave a note in the MR so we know we need to trigger the CI.

Merge request reports

Loading
Loading