Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Publish an APK upon each release #1515

Open
emersonian opened this issue Jul 15, 2024 · 4 comments
Open

Publish an APK upon each release #1515

emersonian opened this issue Jul 15, 2024 · 4 comments

Comments

@emersonian
Copy link

Is your feature request related to a problem? Please describe.

Android users who opt out of using Google cannot currently install Zashi without building it from source.

An example is users of GrapheneOS.

Describe the solution you'd like

Have CI publish an official APK for Zashi on Github upon each release.

Alternatives you've considered

F-Droid is another great place to publish, but releasing an APK is a must for users that want to install Zashi without depending on any app stores.

Additional context

Follow in the footsteps of Signal, Proton, Bitwarden, and many wallet apps. Publishing an APK is a privacy best practice in the Android ecosystem.

Not publishing an APK is actually a security risk because scraper sites like APKPure, APKCombo, end up hosting your app's APK without your team's permission or knowledge, presumably scraped from the Google Play store. This can be a way that users encounter malware-compromised builds of your software.

Related ecosystem APKs:

@HonzaR
Copy link
Collaborator

HonzaR commented Jul 15, 2024

Hi @emersonian, this is a great idea. We have already discussed this internally some time back. We could go the GitHub releases way until we decide which server/website we'd like to deploy to. Users can poll different APKs from GitHub even now from GitHub -> Actions -> Deploy/Pull Request -> Artifacts -> Binaries (like from this), which contains release/debug/mainnet/testnet variations of APKs, although this way is not that user-friendly.

@emersonian
Copy link
Author

Great to hear! I believe the CI build artifacts expire after a period of time, so yes I'm all about a more user friendly approach that serves as a permanent archive. Being able to access all previous builds will also aid security auditors and facilitate QA regression tests (2026: "does Zashi v0.x still work with today's chain and nodes?").

Thanks for the quick response.

@stokito
Copy link

stokito commented Aug 27, 2024

The F-Droid build is important. Currently there is only one app with the ZCash support

@HonzaR
Copy link
Collaborator

HonzaR commented Sep 2, 2024

Hi @stokito, Thanks for the message! We already started with the F-Droid integration but needed to move on to other tasks. Hopefully, we'll be able to finish it in the upcoming weeks.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants