GitHub Action that syncs APK releases from a source repository into an F-Droid binary repository. It detects new releases, downloads APK assets, extracts app metadata, verifies the signing certificate, and commits the updated APK + index back to your F-Droid repo.
name: Sync to F-Droid
on:
schedule:
- cron: "0 3 * * *" # nightly poll
workflow_dispatch:
jobs:
sync:
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
steps:
- uses: actions/checkout@v4
with:
repository: your-org/your-fdroid-repo
token: ${{ secrets.GITHUB_TOKEN }}
- uses: livrasand/gh-fdroid-release
with:
token: ${{ secrets.GITHUB_TOKEN }}
source: your-org/your-app-repo # owner/repo that publishes APKs
apk: "*.apk"
release: latest
repo-directory: repo
verify-signature: "true"| Input | Required | Default | Description |
|---|---|---|---|
token |
yes | — | GitHub token with repo scope |
source |
yes | — | Source repository (owner/repo) to fetch releases from |
apk |
no | *.apk |
APK asset name or glob pattern to match in the release |
release |
no | latest |
Release to sync: latest or a specific tag like v1.0.0 |
repo-directory |
no | repo |
Directory where APKs are stored in your F-Droid repo |
verify-signature |
no | true |
Abort if the APK's signing certificate differs from the previous version |
commit-message |
no | auto | Custom commit message; supports {package}, {version}, {versionCode} |
create-pr |
no | false |
Create a pull request instead of pushing directly |
| Output | Description |
|---|---|
updated |
true if a new APK was synced, false if already up to date |
package |
Package name extracted from the APK |
version |
Version name extracted from the APK |
version-code |
Version code extracted from the APK |
sha256 |
SHA-256 hash of the synced APK |
- Fetch the release (
latestor a specific tag) from the source repo. - Find APK assets matching the
apkpattern. - Download the APKs to a temp directory.
- Extract
packageName,versionName, andversionCodeviaaapt2(falls back to parsing the binaryAndroidManifest.xml). - If
verify-signatureis enabled, compare the new APK's signing certificate SHA-256 fingerprint against the previous version in your repo. A mismatch aborts the job. - Skip if that exact version is already published.
- Copy the APKs into your
repo/directory. - Run
fdroid updateto regenerate the index; iffdroidserveris unavailable, generate a minimalindex.xmlinstead. - Commit and push (creating a PR if
create-pris set).
- The workflow must run on
ubuntu-latest(needskeytoolfrom the JRE for signature checks;aapt2is tried first and falls back gracefully). - Your F-Droid repo's workflow needs
contents: write(andpull-requests: writeif usingcreate-pr). - Using real
fdroid updaterequiresfdroidserverinstalled on the runner (e.g.pip install fdroidserver) and a configured F-Droid repo key (e.g.keystore.properties).
GPL-3.0 — see LICENSE.md.