Free to list, always.No paid rankings. Every recommendation explains its trade-offs.
OpenSourceChoice
Security

F-Droid 2.0: Wait for the Rollout Before You Upgrade

F-Droid 2.0 modernizes search and updates, but rollout status and missing safety features make a staged upgrade safer for existing users.

Last reviewed
Evidence
3 official sources
F-DroidAndroidApp StoresPrivacyMobile SecurityOpen Source
F-Droid 2.0: Wait for the Rollout Before You Upgrade

OpenSourceChoice verdict: existing F-Droid users should wait until version 2.0 is offered through the normal suggested-version rollout, then test it on one non-critical device before upgrading everywhere. Do not force the current beta-channel package if you depend on Android 6, F-Droid Privileged Extension, automatic Tor detection, the panic-trigger app-wipe action, or the unfinished Nearby replacement. New users on Android 7 or later can pilot 2.0 now; users who do not need Nearby or panic features should compare F-Droid Basic.

This researched analysis was checked on September 25, 2026. We reviewed the release announcement, package metadata, signed tag, repository activity, current issues, security documentation and public discussion. We did not install the APK, test an Android device or audit the source.

The decision at a glance

QuestionAssessment
Current release2.0.0, tagged September 22 and added to the repository September 23; still marked beta while the rollout proceeds
Best fitAndroid 7+ users who want better search, filtering and background updates and can tolerate an early rollout
Poor fitUsers relying on app wipe, FPE, Android 6, automatic Tor detection or the new Nearby implementation
Main riskA major rewrite changes safety-sensitive behavior while the final package is not yet the suggested update
Real costReviewing migrated settings, permissions, repositories and update behavior, plus keeping a tested recovery path
Alternative to evaluateF-Droid Basic when Nearby and panic features are unnecessary

Why this matters now

F-Droid announced 2.0 on September 24 after more than a year of work and 14 test releases. It is the official client's largest redesign in a decade: major components were rewritten with Kotlin and Jetpack Compose, while discovery, search, filtering and installation were reworked.

The Hacker News discussion reached about 990 points and 268 comments during our check. Separate r/Android and r/linux threads reached roughly 830 and 610 votes. Those independent signals show that users are making an upgrade decision now; they do not prove reliability.

The rollout state matters more. F-Droid says 2.0 will reach users over the coming weeks. Its package page lists 2.0.0 as beta, and the FAQ says unsuggested versions can require “Allow beta updates.” A final-looking number is not a broad recommendation.

What 2.0 does—and what it does not

The new client consolidates navigation into Discover, Search and My Apps. Search covers descriptions, categories and translations, with better CJK handling. Filters can combine compatibility, categories and anti-features. On supported devices, a pre-approval API moves installation consent before the download, while background checks reduce manual refreshes.

F-Droid remains a repository client, not an Android security scanner. It verifies index signatures and APK hashes and shows anti-features. It cannot certify every app, protect an abandoned dependency or make a third-party repository trustworthy. The AUR incident runbook explains the same boundary: provenance controls do not replace application review.

The rewrite does not preserve every 1.x behavior. Android 6 and FPE are unsupported. Tor auto-detection became generic proxy settings, with Tor VPN recommended. App hiding changes only the icon and name. Panic-trigger app removal and wiping has not returned; F-Droid advises dependent users to postpone. The redesigned Nearby implementation is still in development.

Who should upgrade, and who should wait

Pilot 2.0 on a spare Android 7+ phone or work profile when F-Droid is not part of a personal-safety procedure. A failed install must not block an essential tool.

Wait for the suggested update if you manage several devices or depend on unattended updates. One post-launch issue reports new installations failing on one Vivo/iQOO Android 14 device while existing-app updates worked. It is a single device-specific report, not evidence of a general failure, but it is a useful early compatibility signal.

Do not upgrade when panic-trigger app removal is part of a safety plan. A cosmetic disguise is not deletion, and the app remains detectable. Users of integrated Android distributions should follow their OS maintainer's tested package path.

Privacy, security and trust boundaries

F-Droid says the client does not track users. It still contacts selected repositories and mirrors, and the full client can query installed packages to identify updates. Its broader permissions also support installation and Nearby/panic functions. Review them against the features you use.

The official package page says the 2.0.0 APK is F-Droid-built and signed and corresponds to the linked source. The signed 2.0.0 tag points to commit 30f467b2c6b8f661191a70ae004af933dad5b5f0. F-Droid also publishes its APK certificate and security model. Prefer the client repository: direct APK downloads lack update notifications and are labeled less secure.

The project says Open Technology Fund's Security Lab and Convocation reviewed 2.0 and relevant findings were addressed. The report was not public at our cutoff, so its scope and residual risks cannot yet be independently assessed. A signed security.txt publishes private reporting channels.

License, maintenance and operational cost

F-Droid Client is GPL-3.0-or-later, unchanged from 1.23.2. There is no license fee; tagged source, APK signature and build log are public. Copyleft matters if you distribute a modified client, while each catalogue app keeps its own license. See our open-source license guide.

The cost is operational: data and battery for background checks, added trust for every repository, device testing and issue monitoring. Nine commits landed after the tag before our cutoff, including panic-mode and CI work. That pace is encouraging, but the rollout is still settling.

Compare F-Droid Basic

F-Droid Basic uses the same codebase but omits Nearby and panic. Its 2.0.0 package is also beta, requires Android 7+ and requests fewer permissions. It can use modern Android's unattended-update path without root or FPE.

Choose Basic to browse, install and update repository apps without the extra feature surface. Third-party clients add another maintainer, release and security-policy decision; compare them separately.

A measurable seven-day pilot

  1. Use one non-critical Android 7+ device or work profile. Record version, repositories, mirrors, proxy/Tor and update settings.
  2. Accept 2.0 only through F-Droid. Record its version and certificate fingerprint.
  3. Confirm every migrated repository and network/update preference.
  4. Install three test apps, update five, uninstall two and reboot twice. Exercise Wi-Fi and the permitted mobile-data policy.
  5. Verify notifications, manual refresh, proxy or Tor VPN routing, permissions and recovery from a cancelled install.
  6. Pass with no unexplained repository changes, signature warnings, failed operations across 20 attempts or data-policy violations.
  7. Keep 1.23.2 elsewhere until the pilot passes and 2.0 becomes suggested. Stop if a required safety feature is missing.

Conclusion

F-Droid 2.0 modernizes discovery and installation. It is also a staged rollout of a large rewrite whose package is still beta and whose audit is not yet public.

Wait for the suggested channel, then prove installation, updates, privacy settings and recovery on one device. Users relying on FPE, Android 6, Nearby or panic-trigger app wiping should remain on 1.x until their dependency has a supported replacement.

Sources and research record

Sources were accessed September 25, 2026. Social counts are point-in-time interest signals, not reliability evidence. OpenSourceChoice performed no hands-on Android testing.

Turn research into an architecture

Build a stack for this use case.

Answer nine practical questions and compare three transparent architectures with costs, free limits, lock-in, and migration paths.

Build my stack