External Publication
Visit Post

Add information about who built the source code and signatures and reproducibility

F-Droid Forum [Unofficial] April 11, 2026
Source

When using your app, the F-Droid interface doesn’t provide information about who built the app from source, who signed the app, or whether the app can be reproduced from source code. This information is only available on the website when viewed in a browser, but it’s not included in the main f-droid.apk app.

Please add important information: who compiled the app, who signed it, and how the compatibility check was performed. It’s possible that the app is open source, but the developer added unnecessary hidden functionality during compilation, then signed the app with their key and uploaded it to the f-droid directory. Without verifying that the app complies with the source code, its security cannot be guaranteed.

Discussion in the ATmosphere

Loading comments...