Repository navigation
XPENC v1.1.3 is on F-Droid #2
Closed
PATILYASHH
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
XPENC v1.1.3 is live on F-Droid:
f-droid.org/packages/com.yash.xpenc
Why this one matters
F-Droid doesn't redistribute a binary I built. They build XPENC from this
source tree, on their own infrastructure, and sign it with their key.
For a money app that claim is the whole point. Until today, "no server, no
sign-up, your data never leaves the phone" was something you had to take my
word for — you were installing an APK I compiled on my machine and uploaded.
Now a third party compiles the same source you can read and confirms the
output matches. You no longer have to trust me. You can check.
You also get automatic updates and the right ABI picked for your phone,
which is a nice consolation prize.
The F-Droid build and the GitHub APK are signed with different keys.
Android will not update one over the other, and it will not let you install
one on top of the other. There is no way around this — it's Android's
signature check doing exactly what it should.
Migrating means uninstalling, and uninstalling deletes your ledger. There
is no server, no account, and no cloud copy. If you skip the export, your data
is gone and I cannot get it back for you.
The order matters:
(email it to yourself, drop it in Files, anywhere that survives).
If you're happy on the GitHub APK, you don't have to move at all — Releases
keep working exactly as before. This is an option, not a migration deadline.
Where 1.1.x stands
1.1.1 → 1.1.3 were packaging-only releases driven by the F-Droid review
(versionCode scheme, Flutter pin, AGP dependency-metadata block). No
functional changes since 1.1.0 — full detail in the
changelog.
Bank-SMS auto-capture is still paused. It shipped in 1.0, but the
READ_SMSpermission made Play Protect block direct APK installs, so 1.1.0dropped it — the app now requests no SMS permission at all, only notifications.
The on-device pipeline (parser, dedupe, review cards, Auto-Approve with real
Undo) is intact and comes back in a form that doesn't trip Play Protect. Bank
template contributions are still welcome and still the best first contribution
to this repo: see
CONTRIBUTING.
Install trouble or a migration that went sideways → Install & backup.
Anything else → Q&A.
All reactions