Skip to content

Publisher

F-Droid

Verified publisher

F-Droid is a catalogue of free and open-source Android software. It builds apps from their published source and signs the results itself, then publishes the signing certificate and a SHA-256 for every build — which is why we can import from it without weakening what a listing here is supposed to mean. Apps imported from F-Droid are grouped under this profile for provenance; each one credits its own author, who wrote it.

3217

apps listed

Apps from F-Droid

Each listing below carries the hash and certificate fingerprint for its current build. Because these apps share a publisher, they also share a signing key — which means a build that claims to come from F-Droid but presents a different fingerprint is telling you something useful.

Kotori

Gabriel Ibáñez

v4.2.04.2 MBAndroid API 16+

KouChat

Christian Ihle

v1.1.12.5 MBAndroid API 16+

koyu.space

koyu.space

v3.319.4 MBAndroid 5.0+

krassesSpiel

F-Droid

v1.1.43 MBAndroid API 16+

KryptEY

amnesica

v0.1.516.6 MBAndroid 8.0+

Kumquats

Dozing Cat Software

v1.1.119.7 MBAndroid API 16+

Kwik DEM (ant.spl)

F-Droid

v1.1127.4 MBAndroid API 9+

Kwik DEM (eur.rus)

F-Droid

v1.1183.1 MBAndroid API 9+

Kwik DEM (pan.arg)

F-Droid

v1.1134.2 MBAndroid API 9+

Kwik DEM (sah.jap)

F-Droid

v1.1171.4 MBAndroid API 9+

Kwik DEM (usa.can)

F-Droid

v1.1157.9 MBAndroid API 9+

Kwik DEM (zar.aus)

F-Droid

v1.1121.8 MBAndroid API 9+

Kwik EFIS

F-Droid

v8.034.1 MBAndroid API 9+

Kwik EFIS (E-Ink)

F-Droid

v8.032.8 MBAndroid API 9+
📚

La et Le

Seweryn Polec

v7.1.162.1 MBAndroid 7.0+

la/u/ncher

Niles Rogoff

v4.2.553.2 MBAndroid API 16+

LaaNo

Aleksandr Borisenko

v0.3.42.3 MBAndroid API 19+

Lab+ for Gitlab

thelooter

v1.5.030.3 MBAndroid 5.0+

Page 59 of 135

Definition

What “verified publisher” means here

It is a claim about identity, not about quality. A verified publisher on APKBrowse has demonstrated two things: that they control the domain their software ships from, and that they control the signing key their builds are signed with. We check the second against the first — a build arriving from the publisher's own release channel, signed with the key we already have on file for them, is one we can attribute with confidence.

That attribution is the whole point. Once a certificate fingerprint is recorded against a publisher, every later release can be checked against it, and anything signed with a different key stops looking like an update and starts looking like a different app wearing the same name. Android enforces this rule at install time regardless of what we say — it will refuse an update signed with a key that does not match the version already on the device. We are simply making the fingerprint visible before you get that far.

What the badge does not mean: that we have audited the code, that we endorse the app, or that the privacy policy is any good. Those are separate questions, and a verified publisher can still ship something you would rather not install. Verification tells you who wrote it. Deciding whether to trust them is still yours.