F-Droid 2.0 arrives with app rewritten in Kotlin and Compose, biggest change in 10 years
After more than a year of work and 14 test releases, F-Droid launches the biggest update of the decade: simplified navigation, frictionless installation, and a new chapter for those distributing Android apps outside the Play Store.
O F-Droid, an open-source repository and client that has existed for more than ten years as an alternative to the Google Play Store, announced on September 24, 2026 the release of F-Droid 2.0. According to the official post, it is the app's biggest update in a decade, the result of more than a year of work and 14 test releases before reaching the public. The rollout to users begins in the coming weeks.
For those who only use F-Droid as a source of apps, the most visible change is to the interface. For those who develop, package, or maintain apps distributed through this channel, the list of technical changes is more interesting: a complete rewrite of the client, a new installer, a different update policy, and a step back on at least one security feature that did not return in this version.
From Java/XML to Kotlin with Compose
The F-Droid team rewrote the app's core components using Kotlin and Jetpack Compose, which the announcement itself calls "the standard toolkit" for Android today. The justification isn't only aesthetic: according to the post, the explicit goal was to lower the barrier to entry for new contributors, since Android development has changed a lot over the past decade and the old codebase no longer reflected current practices.

The practical effect, for those who already contribute or are thinking about contributing to the project, is a codebase more aligned with Material Design and easier to test and extend. Development of the new version was funded by NLnet through the Mobifree fund, with Torsten Grote as lead developer, and went through an independent security review conducted by the Open Technology Fund's Security Lab together with Convocation. The full audit report has not yet been published.
One side effect of the modernization: F-Droid 2.0 requires a fix that only exists from Android 7 onward, so support for Android 6 has been discontinued in the new client (older versions of F-Droid still work on older Android devices).
Frictionless installation, thanks (in part) to regulatory pressure
The most relevant change for those distributing software outside the Play Store is the new unified installer. The post is direct in saying that, historically, the flow of installing or updating an app through F-Droid was "forced to be second-class" by Android. That has changed because the system now offers any app store a pre-approval API, a change the announcement attributes "in large part" to pressure from the European Union's Digital Markets Act and antitrust actions in other countries.
With the new API, the user confirms the installation as soon as they decide to install, rather than after the APK has already been downloaded, bringing the experience closer to what the Play Store natively offers. This matters for those who currently avoid publishing on F-Droid because they find the installation onboarding too slow to convince non-technical users: the friction gap compared to an official store shrinks.
The app now also checks for and installs updates automatically in the background by default (those who prefer manual control can still turn this off). The pull-to-refresh gesture, used by many people to force a check of all repositories, has been removed: it now only serves to scroll the screen, and manually triggering an update has been moved to the "three-dot" menu on the My Apps screen.
Discovery and search redesigned
With thousands of apps in the repository, navigation has been reorganized into three areas: Discover, Search, and My Apps. The category system was expanded with more specific categories (VPNs, firewalls, password managers, browsing) grouped into "meta-categories" to make exploration easier. The games category, as an example given by the team itself, now distinguishes 17 different genres instead of lumping everything together as "Games".

Search now indexes descriptions, categories, and translated content, not just the app name, and gained better support for searches in Chinese, Japanese, and Korean. Filters combine category, device compatibility, and anti-features, allowing, for example, listing only action games compatible with the device and excluding apps that depend on non-free network services. For devs who publish to the repository, this reinforces the weight of well-filled-out metadata (category, anti-features, translated description) in organic discovery within the app.
Security and privacy: what changed and what didn't come back
F-Droid has long offered features aimed at users in at-risk contexts, such as Tor support (via Tor Onion Services for repositories and mirrors) and so-called "panic" features, which wipe sensitive information from the device in emergencies. In version 2.0, Tor configuration was simplified: the old auto-detection, which was no longer reliable, was removed, and anyone who had "Use Tor" enabled is migrated to a generic Proxy setting. The recommended path now is to use a dedicated TorVPN.
The app's disguise feature (which made F-Droid pass itself off as a calculator) was simplified to follow the pattern adopted by apps like Orbot, TorVPN, and Signal: the disguise now only changes the icon and name, not the app's behavior, and F-Droid still shows up in the system's app settings and is detectable in a forensic examination. The team justifies the change as a way to help users better understand the real limits of the protection.
One feature did not return: the ability to automatically remove and delete apps in response to an external panic trigger, such as the Ripple app. According to the post, maintaining this feature requires very specialized work for a small user base, and the team chose not to let it hold back the rest of the improvements. Anyone who relies on this specific function is advised to delay updating to 2.0.
Another relevant technical change: the F-Droid Privileged Extension (FPE), used by custom ROMs to give F-Droid silent-installation privileges, is not supported by 2.0. Instead, the app now relies on Android's native session installer, which allows background updates on any recent version of the system without needing FPE. This directly affects distributions like CalyxOS, LineageOS for microG, iodéOS, emteriaOS, and ShiftOS, which bundle F-Droid by default and will need to keep an eye on how this transition behaves in their builds.
The backdrop: why this matters now
The F-Droid post itself opens with a warning that isn't technical but contextual: "F-Droid is under threat. Google is changing the way you install apps on your device," with a link to the keepandroidopen.org campaign. The announcement doesn't detail Google's change, but placing this warning alongside the 2.0 release is no coincidence: F-Droid is investing heavily in making installation outside the Play Store more seamless right at the moment it describes pressure from Google itself over how apps are installed outside the official store. For Brazilian devs who currently distribute open-source builds via F-Droid, direct APK sideloading, or alternative stores, this is the kind of signal worth watching closely, because it changes distribution rules without going through the Play Store.
What's still missing
The complete rewrite of Nearby, the feature that lets you share apps between devices without a central server, did not make it into this initial version. According to the announcement, the work is in progress, with new connection methods already in development, and the team explicitly asks for help from Nearby users to test and shape the next generation of the feature before it reaches a wider audience.
The full report of the security audit conducted by the OTF Security Lab and Convocation has also not yet been published. And, as with any redesign of this size, some decisions (the absence of panic-trigger app-wiping, the drop in FPE support) are reversible depending on community feedback in the coming months, something the team itself reinforces by calling 2.0 the "beginning of the next chapter," not a final stopping point.
Translated from the Brazilian Portuguese original · Read the original
Supabase has 16,000 databases with exposed personal data, research finds
A survey by UpGuard found names, addresses, passwords and tokens publicly accessible in thousands of projects hosted on the platform, almost always due to a configuration mistake by the developer themselves.