That's it. Would you recommended any other repository?

all 49 comments

sorted by: hot top controversial new old
[–] 27 points 2 years ago (1 child)

I keep it simple so I can confidently download the apps.

I can't keep track of which repos are safe, and we've seen posts on here from people getting sketchy apps from a repo they added.

I'm sure there are other safe repos, and I'm willing to add one if people recommend an app that requires it, but I'll probably remove it afterwards.

  • source
  • hideshow 2 child comments
  • [–] 13 points 2 years ago (1 child)

    This is a good approach. I would not even use Izzy's repo shown by OP (at least not on a daily driver device - great for testing newer apps I'm sure) because I don't see it as advantageous to get updates so quickly or access to apps that are not yet (or will never be) fully open source.

    Basically I see most of the value of F-Droid in their build server and official repo. So I only add repos with a very short list of apps, like microg and KDE.

    I can always install the odd apk manually, or use Aurora store (preferably in the work profile)

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago (1 child)

    Yeah. F-droid's defaults for me have always worked well, and if I want a specific app to be up to date, I'll download it right from the devs (Shattered Pixel)

  • source
  • parent
  • hideshow 2 child comments
  • [–] 22 points 2 years ago

    Wow thanks for this post. Today I learned about Fdroid Repos. (Feeling sheepishly stupid but slight more informed now.)

  • source
  • [–] 12 points 2 years ago

    I like Kde Itinerary for traveling so I add the Kde Android repo

  • source
  • [–] 12 points 2 years ago (1 child)

    I installed droid-ify, an alternative front-end for F-Droid, it comes with a whole bunch of repo's by default.

  • source
  • hideshow 2 child comments
  • [–] 9 points 2 years ago*

    Droid-ify has a lot more by default (but unticked). You can have a look and see what you could use. I use cromite and mulch as navigators, and you can find them there (cromite repo and divestOS repo)

  • source
  • [–] 8 points 2 years ago (1 child)

    I wouldn't personally even use IzzyonDroid. The only other F-droid repo I use is cromite

  • source
  • hideshow 2 child comments
  • [–] [S] 5 points 2 years ago* (2 children)

    Why not? Not reliable? Not safe? I'm re-learning (stuff got obsolete since last time I was interested)

  • source
  • parent
  • hideshow 4 child comments
  • [–] 5 points 2 years ago (1 child)

    Izzyondroid isn't as strict when it comes to the software they package

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 4 points 2 years ago (1 child)

    Good to know. Added it because I read it had some extra apps. I'm trying new stuff

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 2 years ago (1 child)

    And that is a fair answer. My long term concern is that developers will start taking the easy route more and more instead of adhering to F-Droid's fairly high standard.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 6 points 2 years ago* (last edited 2 years ago) (1 child)

    Yep some of the big guys aldready do that they add available on fdroid and i get excited and click then it brings me to izzy and i get dissapointed.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 2 years ago (1 child)

    I like to add as many repos as I can.
    The more apps in F-Droid,
    the less reason to go to GooglePlay :)

    Here is a list with all repo's I've got imported:

    I usually keep the Archive variants disabled,
    but they're nice to keep around,
    for if you ever need an old version of an app.

    Also,
    most of these I've found through Droid-Ify,
    it's my favorite app to manage my F-Droid apps: https://f-droid.org/packages/com.looker.droidify/

  • source
  • hideshow 2 child comments
  • [–] 7 points 2 years ago (1 child)
  • [–] 4 points 2 years ago (1 child)

    I prefer Tubular to Newpipe. This version of newpipe has Sponsorblock.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago (3 children)

    I'm conflicted about sponsorblock, I usually hate youtuber sponsor (since those are usually scam) but I don't know if there is a more ethical way to earn money from ads, since donations aren't usually enough

  • source
  • parent
  • hideshow 6 child comments
  • [–] [S] 1 point 2 years ago

    Maybe because I'm old enough to remember TV before streaming, I'm not so bothered by a 30 seconds add inside a video. And knowing who sponsors a content creator also gives a bit of context about their possible bias.

  • source
  • parent
  • [–] 5 points 2 years ago* (1 child)

    Futo repo for Futo Voice Input App. Totally free open-source offline speech to text engine. Works better than I expected (for English).

  • source
  • hideshow 2 child comments
  • [–] 5 points 2 years ago (1 child)

    There are general purpose repos and specific app repos. Those for specific apps might allow you to download apps not found elsewhere or they might just get you the update a little faster.

    I have the repos for Collabora and Newpipe enabled on mine for those reasons.

    You might also look at Obtanium if you're looking to keep specific apps updated.

  • source
  • hideshow 2 child comments
  • [–] [S] 1 point 2 years ago* (1 child)

    Is there a real delay on updates? I mean, I'm in an almost 4 year phone with android 10, can't say I run behind the latest stuff

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago

    It depends on the app publisher. The official F-Droid repo has Newpipe version 25.2, which was added August 10, 2023. The Newpipe upstream repo has version 26.1, added December 27, 2023.

  • source
  • parent
  • [–] 3 points 2 years ago*

    I only add some app-specific repos to get more frequent updates on those. Newpipe and Fedilab in particular.
    I know that I could use other tools to install directly from their release images but sticking with F-Droid for now for simplicity.

  • source
  • [–] 1 point 2 years ago (1 child)

    I have active the DivestOS repo, since I use Mull as my main browser. It has also some other nice privacy focused apps.

    https://divestos.org/apks/official/fdroid/repo?fingerprint=e4be8d6abfa4d9d4feef03cdda7ff62a73fd64b75566f6dd4e5e577550be8467

  • source
  • hideshow 2 child comments
  • [–] [S] 1 point 2 years ago (1 child)

    I use mull too, so I'll consider it Does fdroid delay the updates too much?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago (1 child)

    I don't know how much the delay for Mull is specifically, but in general it falls in the range between one and two weeks.
    And since Mull is already behind Firefox in terms of security updates, I think it's better not to fall too much behind

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago (1 child)

    Those are what I use 😁. You can check here for some trusted repo https://t.me/fdroid_repos

  • source
  • hideshow 2 child comments
  • [–] 1 point 2 years ago

    Newpipe and bitwarden?

  • source
  • [–] 0 points 2 years ago* (2 children)
  • [–] 2 points 2 years ago (1 child)

    For a crypto wallet it seems extremely dangerous to use a custom repo. What if one day it pushes an hacked version with the same signature and it takes all the money?

    For this use case I'd consider only from fdroid, the only way it can be sure it matches the published source code

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago (1 child)

    Those repos are maintained by the developers of the Monero wallet. So, if they were going to do that, they would also be able to push the malware version to the fdroid repo as well, because the signatures would match the developers.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago (1 child)

    The fdroid repository has only apps built by fdroid itself using the published source code, while a private repo could have a binary that doesn't match the source.

    It might be a financial incentive for someone to hack the dev, steal their signing keys, silently add a timebomb that at a specific time would send the whole content of the wallet to a specific monero address, replace the apk after a new release is added. Nobody would notice until too late

    Difficult hack but not impossible

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago*

    That is a fair point. The protection of the main fdroid repo is that they build it from source and then compare the binaries to make sure they match if i understand reproduceable builds correctly.

    Edit: But if a hacker hacked the developer, wouldn't they just change the source code as well so that they still match? Like if I wanted to hack Monerujo id want to get the git repo if possible along with the repo keys so i could push malicious code to the git repo, build a binary from that malicious code, publish it on the devs fdroid repo and then when fdroid compares the binary to source they match even though they are malicious.

  • source
  • parent