Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Latest commit

 

History

6 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

F-Droid Release Sync

GitHub Action that syncs APK releases from a source repository into an F-Droid binary repository. It detects new releases, downloads APK assets, extracts app metadata, verifies the signing certificate, and commits the updated APK + index back to your F-Droid repo.

Usage

name: Sync to F-Droid

on:
  schedule:
    - cron: "0 3 * * *"   # nightly poll
  workflow_dispatch:

jobs:
  sync:
    runs-on: ubuntu-latest
    permissions:
      contents: write
      pull-requests: write
    steps:
      - uses: actions/checkout@v4
        with:
          repository: your-org/your-fdroid-repo
          token: ${{ secrets.GITHUB_TOKEN }}

      - uses: livrasand/gh-fdroid-release
        with:
          token: ${{ secrets.GITHUB_TOKEN }}
          source: your-org/your-app-repo   # owner/repo that publishes APKs
          apk: "*.apk"
          release: latest
          repo-directory: repo
          verify-signature: "true"

Inputs

Input Required Default Description
token yes — GitHub token with repo scope
source yes — Source repository (owner/repo) to fetch releases from
apk no *.apk APK asset name or glob pattern to match in the release
release no latest Release to sync: latest or a specific tag like v1.0.0
repo-directory no repo Directory where APKs are stored in your F-Droid repo
verify-signature no true Abort if the APK's signing certificate differs from the previous version
commit-message no auto Custom commit message; supports {package}, {version}, {versionCode}
create-pr no false Create a pull request instead of pushing directly

Outputs

Output Description
updated true if a new APK was synced, false if already up to date
package Package name extracted from the APK
version Version name extracted from the APK
version-code Version code extracted from the APK
sha256 SHA-256 hash of the synced APK

How it works

  1. Fetch the release (latest or a specific tag) from the source repo.
  2. Find APK assets matching the apk pattern.
  3. Download the APKs to a temp directory.
  4. Extract packageName, versionName, and versionCode via aapt2 (falls back to parsing the binary AndroidManifest.xml).
  5. If verify-signature is enabled, compare the new APK's signing certificate SHA-256 fingerprint against the previous version in your repo. A mismatch aborts the job.
  6. Skip if that exact version is already published.
  7. Copy the APKs into your repo/ directory.
  8. Run fdroid update to regenerate the index; if fdroidserver is unavailable, generate a minimal index.xml instead.
  9. Commit and push (creating a PR if create-pr is set).

Requirements

  • The workflow must run on ubuntu-latest (needs keytool from the JRE for signature checks; aapt2 is tried first and falls back gracefully).
  • Your F-Droid repo's workflow needs contents: write (and pull-requests: write if using create-pr).
  • Using real fdroid update requires fdroidserver installed on the runner (e.g. pip install fdroidserver) and a configured F-Droid repo key (e.g. keystore.properties).

License

GPL-3.0 — see LICENSE.md.

About

Automatically sync APK releases from a GitHub repository to an F-Droid repository with metadata extraction, signature verification, and automatic index updates.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Sponsor this project

Contributors

Languages