F-Droid compliance work #16

Closed
opened 2026-07-01 03:11:47 +00:00 by JMR-dev · 0 comments
JMR-dev commented 2026-07-01 03:11:47 +00:00 (Migrated from github.com)

Context

Prepare for F-Droid publication. F-Droid requires a fully FOSS build with no proprietary
dependencies/services and declares "anti-features" for things like network telemetry and
non-free network services. This is treated as a hard constraint across the backlog.

Scope (checklist)

  • Audit dependencies for FOSS licenses; remove/replace any proprietary libs; ensure the
    build is reproducible from source with no non-free Gradle plugins.
  • Anti-feature review of app behaviors:
    • Bug-report pipeline (#10/#11): strictly opt-in and user-initiated, documented — confirm
      it doesn't trip "Tracking"/"NonFreeNet"; declare if unavoidable.
    • Google Backup (#21): off by default / opt-in; declare if needed.
    • Outlook OAuth uses a bundled client id against a proprietary service — document; Gmail is
      app-password IMAP after #9 (no proprietary SDK).
  • Provide F-Droid metadata (fastlane/metadata), a build recipe, and confirm no
    Google/Firebase dependencies.
  • Ensure the app builds without any secrets.properties-gated proprietary keys.

Acceptance criteria

  • A clean-room build yields an installable APK with a documented anti-feature list (ideally
    none, or opt-in only).

Dependencies

Constrains #10/#11/#21 (F-Droid-safe decision). Relates to #20 (README data-flow docs).

## Context Prepare for F-Droid publication. F-Droid requires a fully FOSS build with no proprietary dependencies/services and declares "anti-features" for things like network telemetry and non-free network services. This is treated as a **hard constraint** across the backlog. ## Scope (checklist) - [ ] Audit dependencies for FOSS licenses; remove/replace any proprietary libs; ensure the build is reproducible from source with no non-free Gradle plugins. - [ ] Anti-feature review of app behaviors: - Bug-report pipeline (#10/#11): strictly opt-in and user-initiated, documented — confirm it doesn't trip "Tracking"/"NonFreeNet"; declare if unavoidable. - Google Backup (#21): off by default / opt-in; declare if needed. - Outlook OAuth uses a bundled client id against a proprietary service — document; Gmail is app-password IMAP after #9 (no proprietary SDK). - [ ] Provide F-Droid metadata (fastlane/metadata), a build recipe, and confirm no Google/Firebase dependencies. - [ ] Ensure the app builds without any `secrets.properties`-gated proprietary keys. ## Acceptance criteria - A clean-room build yields an installable APK with a documented anti-feature list (ideally none, or opt-in only). ## Dependencies Constrains #10/#11/#21 (F-Droid-safe decision). Relates to #20 (README data-flow docs).
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: JMR-dev/LibreMail#16