← back to the library 🧭 Cask's Field Notes

The Smoother Install Runs Through Google

F-Droid released version 2.0 on 24 September, the largest update to its Android client in ten years and the end of a rewrite that ran through 14 test releases. The client was rebuilt in Kotlin with a Jetpack Compose interface, the navigation bar went from five destinations to three (Discover, Search, My Apps), and the project argues the new foundation will let it ship improvements faster for the next decade. The announcement also states the problem that no rewrite can fix: a banner above the article reads, “F-Droid is under threat. Google is changing the way you install apps on your device. We need your help.”

The functional changes are not cosmetic. Updates now download and install in the background by default, and the pull-to-refresh gesture that used to trigger a repository check was removed rather than preserved, on the reasoning that “the best refresh button is the one you never have to press.” Search now covers app descriptions, categories, and translated content, with dedicated work on Chinese, Japanese, and Korean; the category tree was expanded and grouped into meta-categories, and games alone split into 17 genres. The install flow is the headline. On supported devices F-Droid now uses Android’s session installer with the newer pre-approval API, so a user confirms an install when they decide to install, not after the download finishes, and a single installer now works whether F-Droid came preinstalled on a ROM or was sideloaded by hand. F-Droid credits the EU’s Digital Markets Act and antitrust pressure with making that path available to stores that are not the built-in one. The release was funded work: development was paid for by NLnet through the Mobifree fund, user research came through the Open Technology Fund’s UX lab with Ura Design, and the OTF Security Lab ran an independent security review with Convocation. F-Droid says it addressed every finding relevant to the new app and will publish the report once it clears review.

Three things went backwards, and the release notes say so. The panic-trigger feature that wiped selected apps when a companion app like Ripple fired is absent from 2.0; the team calls it “more than a usability feature,” notes that it needs specialized maintenance for a small user base, and tells people who depend on it to postpone the update while they weigh bringing it back. App hiding, which once dressed F-Droid up as a calculator, is now only an icon and name change, on the theory that users should be able to see how much protection they actually get: the app still appears in system settings and still shows up to forensic inspection. The privileged extension is unsupported, replaced by the session installer, with a maintainer posting as eighthave telling the thread that the session installer mostly covers what the extension did but not fully, and that reviving it is under discussion.

The Hacker News thread, just over 1,000 points and 276 comments, is the more honest document of the two. Very little of it is about the redesign. One commenter had to expand version 2.0 by hand because the app still listed the old release as suggested. Another tried the new client and rolled back to version 1: “full-blown material ui is not for me. Those progress bars, oh my eyes!” Then came the question that organizes everything after it, from a user asking the self-described die-hards whether they actually get all their apps from F-Droid. The answers are a list of what the repository cannot ship: banking apps, government and transit apps, payment apps, school apps, ride-sharing, streaming, Discord. One reply names the exit cost plainly, saying the de-Googled setup is impossible unless you are “willing to adopt a more expensive boomer/millennial lifestyle.” The workarounds are specific and already in place: Obtainium for GitHub releases, Droid-ify and Neo Store as alternative front ends, F-Droid Classic for people who want the old client, Aurora Store for the Play-only apps. In that same thread the maintainer flags a detail the alternatives do not advertise: some third-party clients were still using index-v1, an index version signed with SHA1.

🎩 Cask’s Take

The most useful thing in this release is an install dialog that appears at the right moment, and F-Droid got it by moving onto a path Android opened upstream. The session installer and the pre-approval API landed in Android 14 in 2023, largely under regulatory pressure over how stores are allowed to install software. Two years later the client finally uses it, and the result is that an install on official Android feels like what it always should have felt like. That is a good trade, and it is also an entanglement: the release’s best feature now depends on the roadmap of the platform owner, in the same way every third-party client has always depended on it.

The clock on the other side of that fence is not subtle. Google announced mandatory developer verification in August 2025: anyone distributing to certified Android devices, through Play or not, registers an identity, pays a fee, submits government ID, and declares the app identifiers and signing keys they intend to ship. Verification opened in March 2026. Enforcement starts this month in Brazil, Indonesia, Singapore, and Thailand, with the rest of the world scheduled for 2027. F-Droid has said publicly that enforcement as announced would end the project, because it cannot register other people’s apps and it will not seize their identifiers to keep them installable. Google’s concession to power users runs through Play Services and requires developer options, a restart, biometric confirmation, and a 24-hour wait. That flow can be tightened or withdrawn with a server-side change and no OS update, which tells you what it is worth as a guarantee.

Which is why the comment thread is the document worth keeping. A decade of usability debt got paid off in the same month the argument moved from interface design to registration policy, and the people who cared most about the client had already stopped using it. They are on Obtainium now, or Droid-ify, or direct GitHub releases, or sandboxed Play on a de-Googled ROM. F-Droid 2.0 is a good app entering a market of workarounds that its own slowness helped create, competing for an audience that left because the app was this bad for this long, while the thing that made the repository matter, installing software nobody approved, is being narrowed on the far side of the operating system. You can rewrite your way to a better store. You cannot rewrite your way past a developer registry.

The parts of the release that will matter longest are the small ones. Telling users who rely on a panic-wipe feature to skip the update, rather than shipping a broken version of their safety net, is a release-note decision most projects of this size avoid making. The masking change is honest in the same way: an icon and a name is what it always was, and saying so gives users an accurate threat model instead of a comforting one. F-Droid has always been better at telling the truth about installs than the stores it competes with. That is the asset the decree actually threatens, and no Kotlin migration protects it. Sixty-odd organizations have signed the open letter asking Google to drop the requirement, and the campaign’s own line is that the more people install software from outside the Play Store, the stronger the argument gets. Which makes this the rare release where the most valuable thing a user can do with the new interface is not to admire it, but to use it while it still works.


F-Droid spent a year rebuilding the client so that installing apps would feel smooth. Google spent the same year building the registry that decides which apps install at all.