F-Droid 2.0 Ships Six Days Before Google's Sideloading Lockdown. Here's What Developers Need to Know
F-Droid 2.0 hit #1 on Hacker News with 1,000+ points. The UI rewrite is nice. The timing is the real story. Google starts enforcing Android developer verification on September 30, 2026 . F-Droid shipped 2.0 on September 24 . Six days. Let's talk about both. What actually shipped F-Droid 2.0 is a ground-up client rewrite, per the official announcement : Kotlin + Jetpack Compose , Material-aligned.…
F-Droid 2.0, a freshly rewritten client, launched on September 24 and quickly found its way to the top of Hacker News with over 1,000 points. The significant news, however, lies not in the UI overhaul, but in the impending Google Android developer verification that begins on September 30, 2026. This new regulation will only allow apps registered to identity-verified developers to be installed on certified Android devices, effectively putting an end to sideloads.
F-Droid's 2.0 release is a complete ground-up rewrite, shifting from Java to Kotlin + Jetpack Compose and adopting a Material-aligned design. The revamped interface includes three tabs - Discover, Search, and My Apps - with settings and Nearby Swap now accessible from the top bar. The search function has also been enhanced to index descriptions, categories, and translations, add CJK support, and remember recent queries.
Auto-updates are enabled by default, harnessing Android's pre-approval install API. However, the new client is limited to Android 7 and above, dropping support for Android 6.
An independent security audit by the Open Technology Fund's Security Lab has been conducted, following 14 test releases and more than a year of development. The feature to 'wipe apps on panic' has been eliminated due to its high maintenance costs. The rollout of the new client will occur gradually over the coming weeks.
Despite the UI enhancements, the most pressing issue for developers is the imminent Google Android developer verification system. For F-Droid, most of its apps are distributed using the F-Droid key rather than the developer's key. This discrepancy poses a significant challenge, as coordination between thousands of independent maintainers and F-Droid does not currently exist.
To mitigate this issue, developers are advised to ensure their reproducible-build status and register their package name in Google's system, even if they do not use the Play Store. Additionally, developers should maintain a stable applicationId and signing setup to avoid any mid-transition complications.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.