Distribution
August 14, 2026 · View on GitHub
Where Cambium is published, what each channel needs, and what remains manual. The target set is every store Amber ships on (GitHub Releases, Obtainium, Zapstore, F-Droid) plus the stores the GrapheneOS project recommends (Accrescent; Obtainium again). GrapheneOS's own Apps store carries first-party GrapheneOS apps only, so it is not a target.
Licence: MIT (LICENSE, detected by GitHub). Donations: GitHub Sponsors
(https://github.com/sponsors/TheCryptoDonkey), Geyser (https://geyser.fund/project/forgesworn)
and Ko-fi (https://ko-fi.com/brays), all declared in .github/FUNDING.yml; the Sponsors URL is
what store metadata points at (F-Droid's Donate: field takes one URL).
| Channel | Status | Signature users get |
|---|---|---|
| GitHub Releases | Live (0.4.3 current; v0.2.0 onward) | Ours (the 0.2.0 trust root) |
| Obtainium | Live via the 0.4.3 GitHub release | Ours |
| Zapstore | Live (0.4.3 current; v0.3.2 onward) | Ours |
| F-Droid | MR open: fdroiddata!42875 — reviewed ("mostly ready"), in the test queue; the fork branch now tracks 0.4.3/versionCode 13 | Ours, when the reproducibility check passes |
| IzzyOnDroid (optional extra) | Eligible; their tracker moved to Codeberg (account needed) | Ours |
| Accrescent | Blocked externally — registration is allowlist-only | Ours |
GitHub Releases (live)
0.4.3 was published and read back on 2026-08-14. Its APK SHA-256 is
857453f021569c9dffc59afc96e295e4b96afe21cd49224b1aecaaa06d65e983, and its signing
certificate matches the 0.2.0 trust root below.
The existing flow: bump versionCode/versionName, tag vX.Y.Z, build with the release
keystore (~/keystores/cambium-release.credentials), upload the APK plus SHA256SUMS, and
include the AppVerifier block in the release notes:
dev.forgesworn.cambium
9E:A1:88:EF:A9:01:5F:7E:7F:90:E1:88:8F:58:6F:52:7B:2A:0E:8A:6D:CD:B3:99:1E:41:FB:4F:14:EE:EF:C6
Obtainium (live)
Nothing to maintain — Obtainium tracks GitHub Releases directly. One-tap add link:
obtainium://add/https://github.com/forgesworn/cambium
Zapstore (live)
Version 0.4.3 was published on 2026-08-14 through the publisher Heartwood bunker connection. The
kind 32267 app, kind 30063 release and kind 3063 file events are live on wss://relay.zapstore.dev
under the publisher identity below. The CDN serves the APK byte-identically to GitHub (SHA-256
857453f021569c9dffc59afc96e295e4b96afe21cd49224b1aecaaa06d65e983) and the matching icon. The
catalog page may take a short while to refresh its release list after relay publication.
First published 2026-07-14 (v0.3.2), signed via a Heartwood bunker:// connection — the
release events (kind 32267 app, 30063 release, 3063 file) are on wss://relay.zapstore.dev
under npub1mgvlrnf… and the APK on Zapstore's CDN is byte-identical to the GitHub release
(same SHA-256). App page:
zapstore.yaml at the repo root is the publishing config. The CLI is zsp
(go install github.com/zapstore/zsp@latest). To publish each future release, after the GitHub
release is up:
SIGN_WITH=<nsec1... | bunker://...> zsp publish --quiet --skip-preview zapstore.yaml
SIGN_WITH also accepts a bunker:// URI, so the release events can be signed by Heartwood
itself rather than a raw nsec on this machine — fitting, and worth doing. Publishing signs three
Nostr events (kind 32267 app metadata, 30063 release, 3063 file metadata) under that npub and
uploads the APK to Zapstore's Blossom CDN.
Publisher identity: npub1mgvlrnf5hm9yf0n5mf9nqmvarhvxkc6remu5ec3vf8r0txqkuk7su0e7q2
(NIP-05 darren@600.wtf, verified to resolve to this key). Zaps on Zapstore flow to the
publishing npub's profile Lightning address — before the first publish, check the kind-0
profile carries lud16: profusemeat89@walletofsatoshi.com so zaps actually route.
The NIP-C1 key link (zsp identity --link-key, tying the APK signing certificate to the npub)
was published 2026-08-13: kind 30509 on the zapstore, damus and primal relays, expiring
2027-08-13 — renew it then. Headless note: zsp identity has no quiet mode, so sign with
--offline | nak event <relays> and feed --verify the npub on stdin; the JKS must be
converted to a temporary PKCS12 for it (keytool -importkeystore), deleted after use.
Each future release: run the same command after the GitHub release is up (the config pulls the latest release), or add it as a release-checklist step.
F-Droid (submission ready)
Everything F-Droid reads from the app repo is now in place: fastlane/metadata/android/en-US/
(title, summary, full description, per-versionCode changelogs, 512×512 icon). Tags are clean
(vX.Y.Z), the licence is MIT, and every dependency comes from Maven Central/Google — including
org.rust-nostr:nostr-sdk, whose prebuilt native AAR has direct precedent: Amber is in official
F-Droid with comparable prebuilt native dependencies from Maven Central.
The submission is done (2026-07-14): the merge request is
fdroiddata!42875, filed from the
fork TheCryptoDonkey/fdroiddata (branch cambium) under the GitLab account TheCryptoDonkey
(created that day via GitHub OAuth). fdroid lint dev.forgesworn.cambium passes locally
(fdroidserver 2.4.5); the fork's own pipeline cannot run until the new GitLab account is
verified for shared runners, which reviewers were told on the MR. Review typically takes days
to a few weeks; reviewers may adjust the build recipe (e.g. a JDK 21 install block, as Amber's
entry carries). Future releases need no new MR, but while the MR is still open the recipe has
to track each new release — add a Builds: entry for the new tag and bump
CurrentVersion/CurrentVersionCode, in docs/fdroid/dev.forgesworn.cambium.yml here and in the
cambium branch of the TheCryptoDonkey/fdroiddata fork. Only once it is merged does
AutoUpdateMode: Version take over and track our tags unattended.
The local draft recipe and the open MR now include 0.4.3/versionCode 13 at source commit
79b2b36b; the fork's cambium branch was updated to commit 269da314 on 2026-08-14. Its reviewed recipe uses Binaries: plus
AllowedAPKSigningKeys: and pins each build to an exact source commit. If
F-Droid's rebuild matches the upstream APK, F-Droid publishes our signed binary; if it does not
match, that version is skipped rather than replaced with an F-Droid-signed build.
Two caveats to state in the MR and be aware of:
- Reproducibility is now the listing gate. The recipe asks F-Droid to rebuild from source, compare the result with our GitHub APK, and publish only the matching upstream-signed binary. That keeps GitHub, Zapstore and F-Droid upgrade-compatible, but a non-reproducible version will be skipped until its difference is fixed.
AutoUpdateMode: Versionmeans future tagged releases are picked up automatically once the MR is merged; only the first listing needs a human. Until then, every release needs the recipe updating by hand (see above).
IzzyOnDroid (optional, low effort)
Not an Amber channel, but popular with the GrapheneOS crowd and served through F-Droid clients.
It indexes our own signed release APKs straight from GitHub Releases (no rebuild, no re-signing,
usually indexed within days). The 19.6 MB APK is within their per-app size budget. Their old
GitLab tracker is now read-only — submissions moved to
https://codeberg.org/IzzyOnDroid/repodata (open an issue with the app-inclusion template; a
Codeberg account is needed). Ready-to-paste text is in docs/fdroid/merge-request.md. Nothing
in-repo is missing.
Accrescent (externally blocked, prerequisites met)
Accrescent is the store the GrapheneOS project recommends first, but developer registration is currently allowlist-only and they are not accepting new allowlist requests (their stated position as of July 2026, while the console matures). There is no submission to make today. Watch https://accrescent.app and their blog for registration opening.
Everything on our side is already satisfied, so when it opens this is quick:
targetSdk35 ✓; release-signed, non-debuggable ✓; no cleartext traffic ✓.- 512×512 PNG icon ✓ (
fastlane/.../images/icon.png, sourceassets/icon.svg). - Upload format is an APK set from
bundletool(≥ 1.11.4), well under the size cap. - App-ID domain verification:
dev.forgesworn.cambiumrequires proving control offorgesworn.dev— we control it (cambium.forgesworn.dev is ours). - No sensitive permissions beyond CAMERA (QR pairing, runtime-requested) and POST_NOTIFICATIONS/foreground service for the opt-in keep-warm toggle — none of the heavily-restricted categories (VPN, accessibility).
Release checklist (all channels, once live)
- Bump
versionCode/versionName, updateCHANGELOG.md, and addfastlane/metadata/android/en-US/changelogs/<versionCode>.txt. - Tag
vX.Y.Z, build, publish the GitHub release (APK + SHA256SUMS + AppVerifier block). SIGN_WITH=... zsp publish --quiet --skip-preview zapstore.yaml, with someone at the Heartwood to confirm the signing request.- While fdroiddata!42875 is still open, add a
Builds:entry for the new tag and bumpCurrentVersion/CurrentVersionCodeindocs/fdroid/dev.forgesworn.cambium.yml, and push the same change to thecambiumbranch of the fdroiddata fork. - Obtainium and IzzyOnDroid pick the release up automatically; F-Droid does too, once the MR in step 4 is merged.