Prepares LibreMail for F-Droid publication. Closes#16.
What's in this PR (mapped to the issue checklist)
1. Dependency license audit — no proprietary libs, no non-free Gradle plugins docs/fdroid-compliance.md §1 records the full audit: every artifact on releaseRuntimeClasspath (via ./gradlew :app:dependencies) and the buildscript/plugin classpath (via buildEnvironment) is FOSS-licensed (Apache-2.0 / BSD-3-Clause / MIT, plus the tri-licensed Jakarta/Angus mail stack used under its BSD/GPL-w-CPE options) and GPL-3.0-or-later-compatible. Confirmed zero Google Play Services / Firebase / analytics artifacts; artifacts resolve only from google() + mavenCentral() (+ Plugin Portal for ktlint/detekt). Nothing needed removing.
2. Anti-feature review (from the actual manifest + source) — none to declare docs/fdroid-compliance.md §2 walks every F-Droid anti-feature with reasoning:
Tracking: no analytics SDK; the debug-report pipeline is off by default, local-only, user-reviewed, and DEBUG_REPORT_ENDPOINT is empty in builds without secrets.properties, so an F-Droid build cannot transmit reports at all.
Google Backup: allowBackup is gated by LibreMailBackupAgent — off by default, opt-in, settings-DataStore-only allowlist.
NonFreeNet: cleared with documented reasoning — LibreMail is a generic IMAP/SMTP client; the Outlook OAuth flow (bundled public client id against login.microsoftonline.com/graph.microsoft.com) only runs when the user adds a Microsoft account, matching the K-9/Thunderbird precedent on F-Droid. Gmail is app-password IMAP (no proprietary SDK). Includes a complete network-surface inventory (§2.4).
One real gap found and fixed: AGP's default dependency-info block (dependency list encrypted with a Google Play key, embedded in the APK signing block) is a known F-Droid blocker — now disabled via dependenciesInfo { includeInApk = false; includeInBundle = false } in app/build.gradle.kts.
4. F-Droid build recipe docs/fdroid/org.libremail.app.yml — a commented template for the fdroiddata metadata/org.libremail.app.yml, with submission instructions (fdroid readmeta / lint / test build). Actually submitting to fdroiddata is out of scope, as agreed.
5. Clean-room build verification docs/fdroid-compliance.md §3: ./gradlew :app:assembleRelease in a checkout with no secrets.properties succeeds (JDK 21) and produces an installable ~12.6 MiB app-release.apk; APK contents inspected — only the three native libs from audited deps (SQLCipher, DataStore, AndroidX graphics-path). The Outlook client id has an in-tree public default and the report endpoint defaults to empty, so no proprietary keys are needed.
Also adds an F-Droid section to the README pointing at the new docs.
Findings for the maintainer (no action taken in this PR)
Tags v0.1.0andv0.2.0 both point at versionCode 1 / versionName "0.1.0" — F-Droid's UpdateCheckMode: Tags needs versionCode bumped per release tag (checklist in docs/fdroid-compliance.md §4).
Release builds fall back to the debug signing key when no keystore is configured (pre-existing, intentional for local installs; irrelevant to F-Droid, which signs its own from-source builds) — documented in §3.
Verification
Fast CI gate green locally: :app:assembleDebug + :app:testDebugUnitTest + :app:lintDebug + :app:ktlintCheck + :app:detekt, plus :app:compileDebugAndroidTestKotlin.
Clean-room :app:assembleRelease (no secrets.properties) — BUILD SUCCESSFUL, APK inspected.
Prepares LibreMail for F-Droid publication. Closes #16.
## What's in this PR (mapped to the issue checklist)
**1. Dependency license audit — no proprietary libs, no non-free Gradle plugins**
`docs/fdroid-compliance.md` §1 records the full audit: every artifact on `releaseRuntimeClasspath` (via `./gradlew :app:dependencies`) and the buildscript/plugin classpath (via `buildEnvironment`) is FOSS-licensed (Apache-2.0 / BSD-3-Clause / MIT, plus the tri-licensed Jakarta/Angus mail stack used under its BSD/GPL-w-CPE options) and GPL-3.0-or-later-compatible. Confirmed **zero** Google Play Services / Firebase / analytics artifacts; artifacts resolve only from `google()` + `mavenCentral()` (+ Plugin Portal for ktlint/detekt). Nothing needed removing.
**2. Anti-feature review (from the actual manifest + source) — none to declare**
`docs/fdroid-compliance.md` §2 walks every F-Droid anti-feature with reasoning:
- *Tracking*: no analytics SDK; the debug-report pipeline is off by default, local-only, user-reviewed, and `DEBUG_REPORT_ENDPOINT` is empty in builds without `secrets.properties`, so an F-Droid build cannot transmit reports at all.
- *Google Backup*: `allowBackup` is gated by `LibreMailBackupAgent` — off by default, opt-in, settings-DataStore-only allowlist.
- *NonFreeNet*: cleared with documented reasoning — LibreMail is a generic IMAP/SMTP client; the Outlook OAuth flow (bundled **public** client id against `login.microsoftonline.com`/`graph.microsoft.com`) only runs when the user adds a Microsoft account, matching the K-9/Thunderbird precedent on F-Droid. Gmail is app-password IMAP (no proprietary SDK). Includes a complete network-surface inventory (§2.4).
- One real gap found and fixed: AGP's default **dependency-info block** (dependency list encrypted with a Google Play key, embedded in the APK signing block) is a known F-Droid blocker — now disabled via `dependenciesInfo { includeInApk = false; includeInBundle = false }` in `app/build.gradle.kts`.
**3. F-Droid metadata (fastlane)**
`fastlane/metadata/android/en-US/`: `title.txt`, `short_description.txt` (66 chars), `full_description.txt` (README-derived), and `changelogs/1.txt` matching versionCode 1. Store-listing `.txt` files intentionally carry no SPDX headers (they render verbatim).
**4. F-Droid build recipe**
`docs/fdroid/org.libremail.app.yml` — a commented template for the fdroiddata `metadata/org.libremail.app.yml`, with submission instructions (`fdroid readmeta` / `lint` / test build). Actually submitting to fdroiddata is out of scope, as agreed.
**5. Clean-room build verification**
`docs/fdroid-compliance.md` §3: `./gradlew :app:assembleRelease` in a checkout with **no `secrets.properties`** succeeds (JDK 21) and produces an installable ~12.6 MiB `app-release.apk`; APK contents inspected — only the three native libs from audited deps (SQLCipher, DataStore, AndroidX graphics-path). The Outlook client id has an in-tree public default and the report endpoint defaults to empty, so no proprietary keys are needed.
Also adds an **F-Droid** section to the README pointing at the new docs.
## Findings for the maintainer (no action taken in this PR)
- Tags `v0.1.0` **and** `v0.2.0` both point at `versionCode 1` / `versionName "0.1.0"` — F-Droid's `UpdateCheckMode: Tags` needs `versionCode` bumped per release tag (checklist in `docs/fdroid-compliance.md` §4).
- Release builds fall back to the debug signing key when no keystore is configured (pre-existing, intentional for local installs; irrelevant to F-Droid, which signs its own from-source builds) — documented in §3.
## Verification
- Fast CI gate green locally: `:app:assembleDebug` + `:app:testDebugUnitTest` + `:app:lintDebug` + `:app:ktlintCheck` + `:app:detekt`, plus `:app:compileDebugAndroidTestKotlin`.
- Clean-room `:app:assembleRelease` (no `secrets.properties`) — BUILD SUCCESSFUL, APK inspected.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Prepares LibreMail for F-Droid publication. Closes #16.
What's in this PR (mapped to the issue checklist)
1. Dependency license audit — no proprietary libs, no non-free Gradle plugins
docs/fdroid-compliance.md§1 records the full audit: every artifact onreleaseRuntimeClasspath(via./gradlew :app:dependencies) and the buildscript/plugin classpath (viabuildEnvironment) is FOSS-licensed (Apache-2.0 / BSD-3-Clause / MIT, plus the tri-licensed Jakarta/Angus mail stack used under its BSD/GPL-w-CPE options) and GPL-3.0-or-later-compatible. Confirmed zero Google Play Services / Firebase / analytics artifacts; artifacts resolve only fromgoogle()+mavenCentral()(+ Plugin Portal for ktlint/detekt). Nothing needed removing.2. Anti-feature review (from the actual manifest + source) — none to declare
docs/fdroid-compliance.md§2 walks every F-Droid anti-feature with reasoning:DEBUG_REPORT_ENDPOINTis empty in builds withoutsecrets.properties, so an F-Droid build cannot transmit reports at all.allowBackupis gated byLibreMailBackupAgent— off by default, opt-in, settings-DataStore-only allowlist.login.microsoftonline.com/graph.microsoft.com) only runs when the user adds a Microsoft account, matching the K-9/Thunderbird precedent on F-Droid. Gmail is app-password IMAP (no proprietary SDK). Includes a complete network-surface inventory (§2.4).dependenciesInfo { includeInApk = false; includeInBundle = false }inapp/build.gradle.kts.3. F-Droid metadata (fastlane)
fastlane/metadata/android/en-US/:title.txt,short_description.txt(66 chars),full_description.txt(README-derived), andchangelogs/1.txtmatching versionCode 1. Store-listing.txtfiles intentionally carry no SPDX headers (they render verbatim).4. F-Droid build recipe
docs/fdroid/org.libremail.app.yml— a commented template for the fdroiddatametadata/org.libremail.app.yml, with submission instructions (fdroid readmeta/lint/ test build). Actually submitting to fdroiddata is out of scope, as agreed.5. Clean-room build verification
docs/fdroid-compliance.md§3:./gradlew :app:assembleReleasein a checkout with nosecrets.propertiessucceeds (JDK 21) and produces an installable ~12.6 MiBapp-release.apk; APK contents inspected — only the three native libs from audited deps (SQLCipher, DataStore, AndroidX graphics-path). The Outlook client id has an in-tree public default and the report endpoint defaults to empty, so no proprietary keys are needed.Also adds an F-Droid section to the README pointing at the new docs.
Findings for the maintainer (no action taken in this PR)
v0.1.0andv0.2.0both point atversionCode 1/versionName "0.1.0"— F-Droid'sUpdateCheckMode: TagsneedsversionCodebumped per release tag (checklist indocs/fdroid-compliance.md§4).Verification
:app:assembleDebug+:app:testDebugUnitTest+:app:lintDebug+:app:ktlintCheck+:app:detekt, plus:app:compileDebugAndroidTestKotlin.:app:assembleRelease(nosecrets.properties) — BUILD SUCCESSFUL, APK inspected.🤖 Generated with Claude Code