<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Padmakar Android</title>
    <description>The latest articles on DEV Community by Padmakar Android (@gargpadmakar).</description>
    <link>https://dev.to/gargpadmakar</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4151500%2F22892962-94dc-474f-bac6-9bd9d530aa8a.jpg</url>
      <title>DEV Community: Padmakar Android</title>
      <link>https://dev.to/gargpadmakar</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/gargpadmakar"/>
    <language>en</language>
    <item>
      <title>How to Publish an Android App on F-Droid: Complete Step-by-Step Guide</title>
      <dc:creator>Padmakar Android</dc:creator>
      <pubDate>Wed, 30 Sep 2026 11:31:16 +0000</pubDate>
      <link>https://dev.to/gargpadmakar/how-to-publish-an-android-app-on-f-droid-complete-step-by-step-guide-3j2p</link>
      <guid>https://dev.to/gargpadmakar/how-to-publish-an-android-app-on-f-droid-complete-step-by-step-guide-3j2p</guid>
      <description>&lt;h1&gt;
  
  
  How to Publish an Android App on F-Droid: Complete Step-by-Step Guide
&lt;/h1&gt;

&lt;p&gt;Publishing an &lt;strong&gt;Android app on F-Droid&lt;/strong&gt; is an excellent way to distribute a free and open-source application to users who prefer an open-source Android ecosystem.&lt;/p&gt;

&lt;p&gt;But publishing on F-Droid is different from simply uploading an APK. Your project needs publicly available source code, an appropriate FOSS license, compatible dependencies, build metadata, application metadata, and a build that F-Droid can reproduce from source.&lt;/p&gt;

&lt;p&gt;In this &lt;strong&gt;F-Droid submission guide&lt;/strong&gt;, I'll walk through the complete process from preparing an Android project to creating an F-Droid Merge Request.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Author:&lt;/strong&gt; Padmakar Garg&lt;br&gt;&lt;br&gt;
Android Developer | Kotlin | Jetpack Compose | Open Source&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  What You Will Learn
&lt;/h2&gt;

&lt;p&gt;By the end of this guide, you will understand:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;How to prepare an Android app for F-Droid&lt;/li&gt;
&lt;li&gt;How to check open-source licenses and dependencies&lt;/li&gt;
&lt;li&gt;How to identify proprietary dependencies&lt;/li&gt;
&lt;li&gt;How to configure &lt;strong&gt;F-Droid Fastlane metadata&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;How to prepare screenshots and app graphics&lt;/li&gt;
&lt;li&gt;How to create a GitHub release and tag&lt;/li&gt;
&lt;li&gt;How to fork the &lt;code&gt;fdroiddata&lt;/code&gt; repository&lt;/li&gt;
&lt;li&gt;How to create &lt;code&gt;metadata/&amp;lt;applicationId&amp;gt;.yml&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;How F-Droid build metadata works&lt;/li&gt;
&lt;li&gt;How to create a GitLab Merge Request&lt;/li&gt;
&lt;li&gt;What to check when an F-Droid build fails&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  F-Droid Publishing Workflow
&lt;/h2&gt;

&lt;p&gt;The complete workflow can be summarized like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Android App
    ↓
Public Source Code
    ↓
FOSS License
    ↓
Dependency &amp;amp; Policy Check
    ↓
Fastlane Metadata
    ↓
GitHub Release / Tag
    ↓
Fork fdroiddata
    ↓
Create YAML Metadata
    ↓
Validate Build
    ↓
GitLab Merge Request
    ↓
F-Droid Review
    ↓
Build &amp;amp; Publication
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  1. Prepare Your Android App
&lt;/h2&gt;

&lt;p&gt;Start with a production-ready Android project.&lt;/p&gt;

&lt;p&gt;Your source repository should contain the real, current source code rather than placeholder files.&lt;/p&gt;

&lt;p&gt;A typical project might look like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;MyAndroidApp/
├── app/
│   ├── src/
│   └── build.gradle.kts
├── fastlane/
│   └── metadata/
│       └── android/
│           └── en-US/
├── gradle/
├── build.gradle.kts
├── settings.gradle.kts
├── LICENSE
└── README.md
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Before starting the F-Droid submission process, verify:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;✓ Repository is public
✓ Source code is complete
✓ Application builds locally
✓ License is included
✓ Dependencies have been reviewed
✓ Application ID is stable
✓ Releases/tags are available
✓ No secrets are committed
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;F-Droid's Quick Start Guide recommends checking the Inclusion Policy before proposing an application. It also requires a public source repository and a FOSS license for apps submitted to the official repository.&lt;/p&gt;




&lt;h2&gt;
  
  
  2. Use a Stable Application ID
&lt;/h2&gt;

&lt;p&gt;Your Android application should use a real, stable production &lt;code&gt;applicationId&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="nf"&gt;android&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nf"&gt;defaultConfig&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;applicationId&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"com.padmakargarg.myapp"&lt;/span&gt;
        &lt;span class="n"&gt;minSdk&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;26&lt;/span&gt;
        &lt;span class="n"&gt;targetSdk&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;36&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Avoid placeholder package names such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;com.example.app
com.example.myapplication
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Use an application ID that you intend to keep stable.&lt;/p&gt;

&lt;h3&gt;
  
  
  Important clarification
&lt;/h3&gt;

&lt;p&gt;Do not assume that every &lt;code&gt;com.example.*&lt;/code&gt; package is automatically rejected by F-Droid as a universal rule. The practical recommendation is to avoid placeholder IDs and use a unique, production-ready application ID.&lt;/p&gt;




&lt;h2&gt;
  
  
  3. Add an Open-Source License
&lt;/h2&gt;

&lt;p&gt;F-Droid focuses on Free and Open Source Software.&lt;/p&gt;

&lt;p&gt;Add a recognized open-source license to your repository.&lt;/p&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;LICENSE
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Common licenses include:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Apache-2.0
MIT
GPL-3.0
LGPL-3.0
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The correct license depends on your project and its dependencies.&lt;/p&gt;

&lt;p&gt;Also review the licenses of third-party libraries used by your Android application.&lt;/p&gt;




&lt;h2&gt;
  
  
  4. Check Your Android Dependencies
&lt;/h2&gt;

&lt;p&gt;This is one of the most important parts of an &lt;strong&gt;F-Droid submission&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;F-Droid's official documentation states that apps submitted to the main repository should use FOSS dependencies. It specifically mentions Firebase and Google Mobile Services as examples of non-FOSS libraries that are not accepted in the official repository.&lt;/p&gt;

&lt;p&gt;For example, review your Gradle dependencies:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="nf"&gt;dependencies&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nf"&gt;implementation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"androidx.core:core-ktx:..."&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;implementation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"androidx.compose.ui:ui:..."&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="nf"&gt;implementation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"androidx.room:room-runtime:..."&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Look carefully for:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Google Mobile Services
Firebase
Closed-source SDKs
Proprietary analytics SDKs
Proprietary advertising SDKs
Closed-source build tools
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If a proprietary dependency is optional, consider whether your application can provide an F-Droid-compatible flavor or implementation without it.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why this matters
&lt;/h3&gt;

&lt;p&gt;F-Droid builds applications from source. Your project therefore needs a build path that works with the tools and dependencies acceptable under F-Droid's policies.&lt;/p&gt;




&lt;h2&gt;
  
  
  5. Set Up F-Droid Fastlane Metadata
&lt;/h2&gt;

&lt;p&gt;F-Droid supports metadata from the upstream app repository, including the &lt;strong&gt;Fastlane metadata structure&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;A common structure is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;fastlane/
└── metadata/
    └── android/
        └── en-US/
            ├── title.txt
            ├── short_description.txt
            ├── full_description.txt
            ├── images/
            │   ├── icon.png
            │   └── phoneScreenshots/
            │       ├── 1.png
            │       ├── 2.png
            │       └── 3.png
            └── changelogs/
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;F-Droid's documentation supports the &lt;code&gt;fastlane/metadata/android/&amp;lt;locale&amp;gt;/&lt;/code&gt; structure for localized descriptions, graphics, screenshots, and changelogs.&lt;/p&gt;




&lt;h2&gt;
  
  
  6. Create &lt;code&gt;title.txt&lt;/code&gt;
&lt;/h2&gt;

&lt;p&gt;Create:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;fastlane/metadata/android/en-US/title.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;My Open Source App
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Keep the title short and consistent with your actual application name.&lt;/p&gt;




&lt;h2&gt;
  
  
  7. Create &lt;code&gt;short_description.txt&lt;/code&gt;
&lt;/h2&gt;

&lt;p&gt;Create:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;fastlane/metadata/android/en-US/short_description.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;A privacy-focused open-source Android application
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Use this field to explain the app's primary purpose in one short sentence.&lt;/p&gt;

&lt;p&gt;Avoid keyword stuffing.&lt;/p&gt;

&lt;p&gt;Instead of:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Android app, open source Android app, F-Droid Android app,
free Android app, privacy Android app...
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;write a natural description:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;A privacy-focused open-source Android application.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  8. Create &lt;code&gt;full_description.txt&lt;/code&gt;
&lt;/h2&gt;

&lt;p&gt;Create:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;fastlane/metadata/android/en-US/full_description.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;My Open Source App is a free and open-source Android application.

Features:

* Simple and modern Android interface
* Privacy-focused design
* Open-source implementation
* Offline-friendly functionality
* Modern Android architecture

The complete source code is publicly available for review and contribution.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Keep the description useful to users rather than writing it only for search engines.&lt;/p&gt;




&lt;h2&gt;
  
  
  9. Add Screenshots and App Graphics
&lt;/h2&gt;

&lt;p&gt;A good F-Droid listing should clearly show what your application does.&lt;/p&gt;

&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;fastlane/
└── metadata/
    └── android/
        └── en-US/
            ├── images/
            │   ├── icon.png
            │   └── phoneScreenshots/
            │       ├── 1.png
            │       ├── 2.png
            │       └── 3.png
            ├── title.txt
            ├── short_description.txt
            └── full_description.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Recommended screenshots:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Home screen&lt;/li&gt;
&lt;li&gt;Main feature&lt;/li&gt;
&lt;li&gt;Important workflow&lt;/li&gt;
&lt;li&gt;Settings&lt;/li&gt;
&lt;li&gt;A screen that demonstrates the app's primary value&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Use real screenshots from your application.&lt;/p&gt;

&lt;p&gt;F-Droid's graphics documentation describes supported screenshot directories such as &lt;code&gt;phoneScreenshots&lt;/code&gt;, &lt;code&gt;sevenInchScreenshots&lt;/code&gt;, &lt;code&gt;tenInchScreenshots&lt;/code&gt;, &lt;code&gt;tvScreenshots&lt;/code&gt;, and &lt;code&gt;wearScreenshots&lt;/code&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  10. Create a GitHub Repository
&lt;/h2&gt;

&lt;p&gt;Push your Android project to a public Git repository.&lt;/p&gt;

&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git init
git add &lt;span class="nb"&gt;.&lt;/span&gt;
git commit &lt;span class="nt"&gt;-m&lt;/span&gt; &lt;span class="s2"&gt;"Initial open source release"&lt;/span&gt;
git branch &lt;span class="nt"&gt;-M&lt;/span&gt; main
git remote add origin https://github.com/USERNAME/REPOSITORY.git
git push &lt;span class="nt"&gt;-u&lt;/span&gt; origin main
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Before continuing, open the repository in a browser and verify that the source code is publicly accessible.&lt;/p&gt;




&lt;h2&gt;
  
  
  11. Create a Release and Git Tag
&lt;/h2&gt;

&lt;p&gt;F-Droid needs a specific source revision to build.&lt;/p&gt;

&lt;p&gt;Create a release tag:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git tag v1.0.0
git push origin v1.0.0
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Your Android project may contain:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="nf"&gt;android&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nf"&gt;defaultConfig&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;versionCode&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
        &lt;span class="n"&gt;versionName&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"1.0.0"&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Make sure the release version and version code correspond to the source revision you submit to F-Droid.&lt;/p&gt;




&lt;h2&gt;
  
  
  12. Fork the F-Droid &lt;code&gt;fdroiddata&lt;/code&gt; Repository
&lt;/h2&gt;

&lt;p&gt;F-Droid maintains application build metadata in the &lt;code&gt;fdroiddata&lt;/code&gt; repository.&lt;/p&gt;

&lt;p&gt;Repository:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://gitlab.com/fdroid/fdroiddata
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Fork the repository to your GitLab account.&lt;/p&gt;

&lt;p&gt;You will eventually add an application metadata file under:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;metadata/
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;metadata/com.padmakargarg.myapp.yml
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  13. Create the F-Droid YAML Metadata File
&lt;/h2&gt;

&lt;p&gt;Create:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;metadata/com.padmakargarg.myapp.yml
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A simplified example is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;Categories&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;Internet&lt;/span&gt;

&lt;span class="na"&gt;License&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Apache-2.0&lt;/span&gt;

&lt;span class="na"&gt;AuthorName&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Padmakar Garg&lt;/span&gt;

&lt;span class="na"&gt;SourceCode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;https://github.com/USERNAME/REPOSITORY&lt;/span&gt;
&lt;span class="na"&gt;IssueTracker&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;https://github.com/USERNAME/REPOSITORY/issues&lt;/span&gt;

&lt;span class="na"&gt;AutoName&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;My Open Source App&lt;/span&gt;

&lt;span class="na"&gt;RepoType&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;git&lt;/span&gt;
&lt;span class="na"&gt;Repo&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;https://github.com/USERNAME/REPOSITORY.git&lt;/span&gt;

&lt;span class="na"&gt;Builds&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;versionName&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;1.0.0&lt;/span&gt;
    &lt;span class="na"&gt;versionCode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;1&lt;/span&gt;
    &lt;span class="na"&gt;commit&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;FULL_COMMIT_HASH&lt;/span&gt;

&lt;span class="na"&gt;AutoUpdateMode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Version&lt;/span&gt;
&lt;span class="na"&gt;UpdateCheckMode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Tags&lt;/span&gt;

&lt;span class="na"&gt;CurrentVersion&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;1.0.0&lt;/span&gt;
&lt;span class="na"&gt;CurrentVersionCode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;1&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Important
&lt;/h3&gt;

&lt;p&gt;This is an example, not a copy-paste universal template.&lt;/p&gt;

&lt;p&gt;Your final metadata must follow the current F-Droid Build Metadata Reference and the requirements of your project.&lt;/p&gt;

&lt;p&gt;Replace:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;USERNAME
REPOSITORY
FULL_COMMIT_HASH
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;with your real values.&lt;/p&gt;




&lt;h2&gt;
  
  
  14. Use the Full Commit Hash
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;commit&lt;/code&gt; field identifies the source revision that F-Droid should build.&lt;/p&gt;

&lt;p&gt;Find your commit hash with:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git rev-parse HEAD
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;7c3f5a8c9d0e1234567890abcdef1234567890abcd
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;F-Droid's Build Metadata Reference recommends using the full commit hash for the build revision.&lt;/p&gt;

&lt;p&gt;This is important because it gives the build process a precise source revision instead of depending on a moving branch.&lt;/p&gt;




&lt;h2&gt;
  
  
  15. Validate Your Android Build
&lt;/h2&gt;

&lt;p&gt;Before creating your Merge Request, test the release build.&lt;/p&gt;

&lt;p&gt;Linux/macOS:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;./gradlew assembleRelease
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Windows:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;\gradlew.bat&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;assembleRelease&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Also verify:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;✓ Build succeeds
✓ Version name is correct
✓ Version code is correct
✓ Dependencies are available
✓ No private files are required
✓ No API keys are required for the build
✓ No signing keys are committed
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Never commit secrets such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;API keys
Passwords
Access tokens
Private certificates
Keystores
Signing keys
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  16. Create a GitLab Branch
&lt;/h2&gt;

&lt;p&gt;Inside your fork of &lt;code&gt;fdroiddata&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git checkout &lt;span class="nt"&gt;-b&lt;/span&gt; add-my-open-source-app
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Add your metadata file:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git add metadata/com.padmakargarg.myapp.yml
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Commit it:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git commit &lt;span class="nt"&gt;-m&lt;/span&gt; &lt;span class="s2"&gt;"New App: My Open Source App"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Push the branch:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git push origin add-my-open-source-app
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  17. Create a Merge Request
&lt;/h2&gt;

&lt;p&gt;Open your fork on GitLab and create a &lt;strong&gt;Merge Request&lt;/strong&gt; targeting the official F-Droid &lt;code&gt;fdroiddata&lt;/code&gt; repository.&lt;/p&gt;

&lt;p&gt;Your Merge Request should make it clear:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Application Name
Application ID
Source Repository
Release Version
Build Information
Important Notes
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;F-Droid's official developer FAQ recommends making a Merge Request to &lt;code&gt;fdroiddata&lt;/code&gt; as the quickest way to request inclusion in the official repository.&lt;/p&gt;




&lt;h2&gt;
  
  
  18. F-Droid Review and Build
&lt;/h2&gt;

&lt;p&gt;After submitting your Merge Request, the metadata and build configuration can go through automated checks and maintainer review.&lt;/p&gt;

&lt;p&gt;The process can include:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Metadata validation
        ↓
Source verification
        ↓
Dependency checks
        ↓
Build checks
        ↓
Policy review
        ↓
Review feedback
        ↓
Merge
        ↓
F-Droid build
        ↓
Publication
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If maintainers request changes, update your branch and push the changes.&lt;/p&gt;

&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git add &lt;span class="nb"&gt;.&lt;/span&gt;
git commit &lt;span class="nt"&gt;-m&lt;/span&gt; &lt;span class="s2"&gt;"Fix F-Droid metadata"&lt;/span&gt;
git push
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Your existing Merge Request can then be updated with the new commit.&lt;/p&gt;




&lt;h1&gt;
  
  
  Common F-Droid Submission Problems
&lt;/h1&gt;

&lt;h2&gt;
  
  
  Problem 1: Proprietary Dependencies
&lt;/h2&gt;

&lt;p&gt;Your application depends on a library or service that does not meet F-Droid's free-software requirements.&lt;/p&gt;

&lt;h3&gt;
  
  
  What to do
&lt;/h3&gt;

&lt;p&gt;Review your dependency tree and determine whether the dependency can be removed or replaced.&lt;/p&gt;

&lt;p&gt;If the dependency is optional, consider an F-Droid-compatible build flavor where appropriate.&lt;/p&gt;




&lt;h2&gt;
  
  
  Problem 2: Missing License
&lt;/h2&gt;

&lt;p&gt;Your source repository does not clearly provide a FOSS license.&lt;/p&gt;

&lt;h3&gt;
  
  
  What to do
&lt;/h3&gt;

&lt;p&gt;Add a recognized license and review the licensing of your dependencies.&lt;/p&gt;




&lt;h2&gt;
  
  
  Problem 3: Version Code Mismatch
&lt;/h2&gt;

&lt;p&gt;Your YAML metadata says:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;versionCode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;10&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;but the Android project produces:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;versionCode = 11
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  What to do
&lt;/h3&gt;

&lt;p&gt;Make sure the F-Droid metadata matches the source revision being built.&lt;/p&gt;




&lt;h2&gt;
  
  
  Problem 4: Wrong Commit
&lt;/h2&gt;

&lt;p&gt;The YAML file points to a source revision that does not contain the expected release.&lt;/p&gt;

&lt;h3&gt;
  
  
  What to do
&lt;/h3&gt;

&lt;p&gt;Check the exact commit:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git rev-parse HEAD
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then verify that the commit contains the intended release.&lt;/p&gt;




&lt;h2&gt;
  
  
  Problem 5: Build Requires Private Configuration
&lt;/h2&gt;

&lt;p&gt;Your project requires a local configuration file or private credential.&lt;/p&gt;

&lt;h3&gt;
  
  
  What to do
&lt;/h3&gt;

&lt;p&gt;Make the build reproducible without exposing secrets.&lt;/p&gt;

&lt;p&gt;For example, avoid committing:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;google-services.json
private API credentials
signing keys
passwords
access tokens
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;when they contain sensitive production information.&lt;/p&gt;




&lt;h1&gt;
  
  
  F-Droid Submission Checklist
&lt;/h1&gt;

&lt;p&gt;Use this checklist before creating your Merge Request:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;☐ Public source repository
☐ FOSS license
☐ Stable application ID
☐ Dependencies reviewed
☐ Proprietary dependencies addressed
☐ Fastlane metadata added
☐ App icon added
☐ Screenshots added
☐ Changelog prepared if needed
☐ Git release/tag created
☐ versionName verified
☐ versionCode verified
☐ Full commit hash verified
☐ F-Droid YAML metadata created
☐ Release build tested
☐ No secrets committed
☐ GitLab branch created
☐ Merge Request created
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h1&gt;
  
  
  F-Droid Metadata Structure at a Glance
&lt;/h1&gt;

&lt;p&gt;Your Android repository can contain:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;MyAndroidApp/
│
├── app/
│
├── fastlane/
│   └── metadata/
│       └── android/
│           └── en-US/
│               ├── title.txt
│               ├── short_description.txt
│               ├── full_description.txt
│               ├── images/
│               │   ├── icon.png
│               │   └── phoneScreenshots/
│               │       ├── 1.png
│               │       ├── 2.png
│               │       └── 3.png
│               └── changelogs/
│
├── LICENSE
├── README.md
├── build.gradle.kts
└── settings.gradle.kts
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;And in the F-Droid repository:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;fdroiddata/
│
└── metadata/
    └── com.padmakargarg.myapp.yml
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h1&gt;
  
  
  Frequently Asked Questions
&lt;/h1&gt;

&lt;h2&gt;
  
  
  Can I publish any Android app on F-Droid?
&lt;/h2&gt;

&lt;p&gt;No. Apps submitted to the official F-Droid repository need to meet F-Droid's inclusion and free-software requirements.&lt;/p&gt;

&lt;p&gt;Check the current Inclusion Policy before submitting.&lt;/p&gt;




&lt;h2&gt;
  
  
  Do I need GitHub?
&lt;/h2&gt;

&lt;p&gt;GitHub is commonly used for hosting the upstream source repository, but the important requirement is that F-Droid can access the source repository and build the application according to its metadata and policies.&lt;/p&gt;




&lt;h2&gt;
  
  
  Do I need GitLab?
&lt;/h2&gt;

&lt;p&gt;For contributing metadata to the official &lt;code&gt;fdroiddata&lt;/code&gt; repository, the submission workflow uses GitLab and Merge Requests.&lt;/p&gt;




&lt;h2&gt;
  
  
  Does F-Droid build the APK from source?
&lt;/h2&gt;

&lt;p&gt;Yes. F-Droid's build system uses source code and build metadata to build applications rather than simply accepting an APK upload as the primary submission mechanism.&lt;/p&gt;




&lt;h2&gt;
  
  
  Can I use Firebase?
&lt;/h2&gt;

&lt;p&gt;Firebase components can create compatibility issues with the official F-Droid repository because F-Droid requires FOSS dependencies. Check the current F-Droid policy and determine whether your application can work without the affected components.&lt;/p&gt;




&lt;h2&gt;
  
  
  What is &lt;code&gt;fdroiddata&lt;/code&gt;?
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;fdroiddata&lt;/code&gt; is the repository containing F-Droid's application metadata and build configuration.&lt;/p&gt;

&lt;p&gt;Each application can have a corresponding YAML metadata file under:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;metadata/&amp;lt;ApplicationID&amp;gt;.yml
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  What is the purpose of &lt;code&gt;Builds&lt;/code&gt; in the YAML file?
&lt;/h2&gt;

&lt;p&gt;The &lt;code&gt;Builds&lt;/code&gt; section tells F-Droid how a particular application version should be built from source.&lt;/p&gt;

&lt;p&gt;A basic build entry contains values such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;Builds&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;versionName&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;1.0.0&lt;/span&gt;
    &lt;span class="na"&gt;versionCode&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;1&lt;/span&gt;
    &lt;span class="na"&gt;commit&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;FULL_COMMIT_HASH&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h1&gt;
  
  
  Official F-Droid Resources
&lt;/h1&gt;

&lt;p&gt;For the latest requirements, always check the official F-Droid documentation because policies and tooling can change.&lt;/p&gt;

&lt;h3&gt;
  
  
  F-Droid Quick Start Guide
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://f-droid.org/en/docs/Submitting_to_F-Droid_Quick_Start_Guide/" rel="noopener noreferrer"&gt;https://f-droid.org/en/docs/Submitting_to_F-Droid_Quick_Start_Guide/&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  F-Droid Build Metadata Reference
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://f-droid.org/en/docs/Build_Metadata_Reference/" rel="noopener noreferrer"&gt;https://f-droid.org/en/docs/Build_Metadata_Reference/&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  F-Droid Descriptions, Graphics &amp;amp; Screenshots
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://f-droid.org/en/docs/All_About_Descriptions_Graphics_and_Screenshots/" rel="noopener noreferrer"&gt;https://f-droid.org/en/docs/All_About_Descriptions_Graphics_and_Screenshots/&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  F-Droid Developer FAQ
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://f-droid.org/en/docs/FAQ_-_App_Developers/" rel="noopener noreferrer"&gt;https://f-droid.org/en/docs/FAQ_-_App_Developers/&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  F-Droid Data Repository
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://gitlab.com/fdroid/fdroiddata" rel="noopener noreferrer"&gt;https://gitlab.com/fdroid/fdroiddata&lt;/a&gt;&lt;/p&gt;




&lt;h1&gt;
  
  
  Final F-Droid Publishing Workflow
&lt;/h1&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;┌─────────────────────────┐
│   Build Android App     │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Make Source Code Public │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Add FOSS License        │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Review Dependencies     │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Add Fastlane Metadata   │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Create Release / Tag    │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Fork fdroiddata         │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Create YAML Metadata    │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Validate Build          │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Create Merge Request    │
└────────────┬────────────┘
             ↓
┌─────────────────────────┐
│ Review → Build → Publish│
└─────────────────────────┘
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h1&gt;
  
  
  Conclusion
&lt;/h1&gt;

&lt;p&gt;Publishing an Android application on F-Droid is a source-first process.&lt;/p&gt;

&lt;p&gt;The most important things to prepare are:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;A &lt;strong&gt;public Android source repository&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;A compatible &lt;strong&gt;FOSS license&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;A dependency tree that meets F-Droid requirements&lt;/li&gt;
&lt;li&gt;Proper &lt;strong&gt;Fastlane metadata&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;App screenshots and graphics&lt;/li&gt;
&lt;li&gt;A versioned source release&lt;/li&gt;
&lt;li&gt;A correct &lt;code&gt;fdroiddata&lt;/code&gt; YAML file&lt;/li&gt;
&lt;li&gt;A reproducible build&lt;/li&gt;
&lt;li&gt;A GitLab Merge Request&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Once you understand these pieces, the &lt;strong&gt;F-Droid submission process&lt;/strong&gt; becomes much easier to follow.&lt;/p&gt;

&lt;p&gt;If you are an Android developer working with &lt;strong&gt;Kotlin, Jetpack Compose, or modern Android architecture&lt;/strong&gt;, this workflow is also a useful introduction to source-based app distribution and reproducible builds.&lt;/p&gt;




&lt;h2&gt;
  
  
  About the Author
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Padmakar Garg&lt;/strong&gt; is an Android Developer specializing in &lt;strong&gt;Kotlin, Jetpack Compose, modern Android architecture, Kotlin Multiplatform, and open-source development&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  Topics
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;how to publish app on F-Droid
how to publish Android app on F-Droid
F-Droid submission guide
F-Droid publishing guide
F-Droid Fastlane metadata
F-Droid Fastlane metadata setup
fdroiddata GitLab
F-Droid YAML metadata
F-Droid Merge Request
F-Droid Android app
open source Android app
publish open source Android app
Android app F-Droid submission
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



</description>
      <category>android</category>
      <category>kotlin</category>
      <category>opensource</category>
      <category>fdroid</category>
    </item>
    <item>
      <title>Android App Security: A Practical Guide to Building Secure Android Applications</title>
      <dc:creator>Padmakar Android</dc:creator>
      <pubDate>Wed, 30 Sep 2026 06:26:31 +0000</pubDate>
      <link>https://dev.to/gargpadmakar/android-app-security-a-practical-guide-to-building-secure-android-applications-3b8l</link>
      <guid>https://dev.to/gargpadmakar/android-app-security-a-practical-guide-to-building-secure-android-applications-3b8l</guid>
      <description>&lt;p&gt;Building an Android application is not only about creating a good UI and&lt;br&gt;
connecting it to an API.&lt;/p&gt;

&lt;p&gt;Modern Android applications handle sensitive information such as&lt;br&gt;
authentication tokens, personal data, financial information, files,&lt;br&gt;
location data, and business-critical operations.&lt;/p&gt;

&lt;p&gt;That makes security an &lt;strong&gt;architectural concern&lt;/strong&gt; --- not something that&lt;br&gt;
should be added just before release.&lt;/p&gt;

&lt;p&gt;One principle every Android developer should understand is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Never treat the Android client as a trusted environment.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The application runs on a device that the developer does not control.&lt;br&gt;
The APK can be inspected, application behavior can be analyzed, network&lt;br&gt;
requests can be observed, and locally stored data can potentially be&lt;br&gt;
accessed on a compromised device.&lt;/p&gt;

&lt;p&gt;So, what should we consider when building a secure Android application?&lt;/p&gt;


&lt;h2&gt;
  
  
  1. Never Store Secrets in the APK
&lt;/h2&gt;

&lt;p&gt;One of the most common mistakes is putting secrets directly into&lt;br&gt;
application code.&lt;/p&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="k"&gt;const&lt;/span&gt; &lt;span class="kd"&gt;val&lt;/span&gt; &lt;span class="py"&gt;SECRET_KEY&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"my-secret-key"&lt;/span&gt;
&lt;span class="k"&gt;const&lt;/span&gt; &lt;span class="kd"&gt;val&lt;/span&gt; &lt;span class="py"&gt;API_KEY&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"123456789"&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;At first glance, this might look harmless.&lt;/p&gt;

&lt;p&gt;But Android applications are distributed to users as APKs or app bundles&lt;br&gt;
that ultimately produce installable application code. An attacker can&lt;br&gt;
obtain an APK and analyze its resources, strings, bytecode, and&lt;br&gt;
behavior.&lt;/p&gt;

&lt;p&gt;Even if you move the value into another file:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="kd"&gt;object&lt;/span&gt; &lt;span class="nc"&gt;AppConfig&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;const&lt;/span&gt; &lt;span class="kd"&gt;val&lt;/span&gt; &lt;span class="py"&gt;API_SECRET&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s"&gt;"super-secret-value"&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;it is still part of the application.&lt;/p&gt;

&lt;p&gt;Changing the location of the secret does not change the security model.&lt;/p&gt;

&lt;h3&gt;
  
  
  What should stay out of the application?
&lt;/h3&gt;

&lt;p&gt;Examples include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Database passwords&lt;/li&gt;
&lt;li&gt;  Private API credentials&lt;/li&gt;
&lt;li&gt;  Backend service credentials&lt;/li&gt;
&lt;li&gt;  Private cryptographic keys&lt;/li&gt;
&lt;li&gt;  Cloud service secrets&lt;/li&gt;
&lt;li&gt;  Signing credentials&lt;/li&gt;
&lt;li&gt;  Administrative credentials&lt;/li&gt;
&lt;li&gt;  Internal service authentication tokens&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These should generally be kept on infrastructure controlled by the&lt;br&gt;
backend.&lt;/p&gt;
&lt;h3&gt;
  
  
  What about API keys?
&lt;/h3&gt;

&lt;p&gt;Not every API key is a secret.&lt;/p&gt;

&lt;p&gt;Some public client identifiers are intentionally distributed with&lt;br&gt;
applications. Certain SDKs require an application identifier that is not&lt;br&gt;
designed to be confidential.&lt;/p&gt;

&lt;p&gt;The important question is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Does possession of this value allow an attacker to perform a&lt;br&gt;
privileged operation?&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;If yes, don't treat the Android APK as a secure place to store it.&lt;/p&gt;


&lt;h2&gt;
  
  
  2. &lt;code&gt;BuildConfig&lt;/code&gt; Is Not a Secret Store
&lt;/h2&gt;

&lt;p&gt;A common approach is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="nf"&gt;buildConfigField&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="s"&gt;"String"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s"&gt;"API_KEY"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s"&gt;"\"my-secret-key\""&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;and then:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="nc"&gt;BuildConfig&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;API_KEY&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This can be useful for configuration, but it does &lt;strong&gt;not&lt;/strong&gt; make a secret&lt;br&gt;
secure.&lt;/p&gt;

&lt;p&gt;The value is still packaged into the application.&lt;/p&gt;

&lt;p&gt;The same applies to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;code&gt;local.properties&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;gradle.properties&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;strings.xml&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;res/raw&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;assets/&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;BuildConfig&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  Kotlin constants&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These can help with configuration management during development, but&lt;br&gt;
they shouldn't be considered a secure runtime secret store.&lt;/p&gt;

&lt;p&gt;A better architecture is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;                    ┌──────────────────┐
                    │   Android App    │
                    └────────┬─────────┘
                             │
                             │ Authenticated Request
                             ▼
                    ┌──────────────────┐
                    │     Backend      │
                    └────────┬─────────┘
                             │
                    ┌────────▼─────────┐
                    │ Secret / Private │
                    │ Configuration    │
                    └──────────────────┘
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The Android application receives only the information it actually needs.&lt;/p&gt;




&lt;h2&gt;
  
  
  3. Never Put Backend Credentials in the Mobile App
&lt;/h2&gt;

&lt;p&gt;Consider an application that needs to communicate with:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Android App
     ↓
Backend API
     ↓
Internal Service
     ↓
Database
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A dangerous design would be:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Android App
     ↓
Internal Service
     ↓
Database
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;with the Android application containing credentials for the internal&lt;br&gt;
service.&lt;/p&gt;

&lt;p&gt;If the APK is compromised, those credentials can potentially be&lt;br&gt;
extracted and reused outside the application.&lt;/p&gt;

&lt;p&gt;A better approach is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Android App
     ↓
Authenticated Backend API
     ↓
Internal Services
     ↓
Database
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The backend becomes the security boundary.&lt;/p&gt;




&lt;h2&gt;
  
  
  4. Authentication Is Not Authorization
&lt;/h2&gt;

&lt;p&gt;These two concepts are often confused.&lt;/p&gt;

&lt;h3&gt;
  
  
  Authentication
&lt;/h3&gt;

&lt;p&gt;Authentication answers:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Who are you?&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Examples include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Username and password&lt;/li&gt;
&lt;li&gt;  OTP&lt;/li&gt;
&lt;li&gt;  Passkeys&lt;/li&gt;
&lt;li&gt;  OAuth&lt;/li&gt;
&lt;li&gt;  Access tokens&lt;/li&gt;
&lt;li&gt;  Biometric unlock&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Authorization
&lt;/h3&gt;

&lt;p&gt;Authorization answers:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;What are you allowed to do?&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;User A → Can access User A's profile
User A → Cannot access User B's profile
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A user can be successfully authenticated and still be unauthorized to&lt;br&gt;
access a particular resource.&lt;/p&gt;

&lt;p&gt;A secure architecture should therefore look like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Android App
     |
     | Request
     ▼
Backend
     |
     ├── Authenticate
     |
     ├── Authorize
     |
     ├── Validate Input
     |
     ├── Check Resource Ownership
     |
     ▼
Response
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Never depend exclusively on Android UI restrictions.&lt;/p&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;isAdmin&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nf"&gt;showAdminPanel&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This controls the UI.&lt;/p&gt;

&lt;p&gt;It does &lt;strong&gt;not&lt;/strong&gt; provide backend authorization.&lt;/p&gt;

&lt;p&gt;An attacker can potentially bypass the UI and call the API directly.&lt;/p&gt;

&lt;p&gt;The backend must enforce the permission.&lt;/p&gt;




&lt;h2&gt;
  
  
  5. Protect Access and Refresh Tokens
&lt;/h2&gt;

&lt;p&gt;Modern applications commonly use access and refresh tokens.&lt;/p&gt;

&lt;p&gt;A simplified model is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Login
  ↓
Access Token
  ↓
API Requests

Refresh Token
  ↓
New Access Token
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The access token should be treated as sensitive information.&lt;/p&gt;

&lt;p&gt;Avoid storing tokens carelessly:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="n"&gt;sharedPreferences&lt;/span&gt;
    &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;edit&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;putString&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"token"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
    &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;apply&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The appropriate storage strategy depends on the application's threat&lt;br&gt;
model and token design.&lt;/p&gt;

&lt;p&gt;For sensitive cryptographic keys, Android provides the &lt;strong&gt;Android&lt;br&gt;
Keystore&lt;/strong&gt; system.&lt;/p&gt;

&lt;p&gt;The architecture should consider:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Token
  ↓
Where is it stored?
  ↓
Who can access it?
  ↓
How long is it valid?
  ↓
Can it be revoked?
  ↓
What happens after logout?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Security isn't simply about where the string is stored.&lt;/p&gt;

&lt;p&gt;Token lifetime, revocation, rotation, server-side validation, and&lt;br&gt;
session management are equally important.&lt;/p&gt;


&lt;h2&gt;
  
  
  6. Android Keystore
&lt;/h2&gt;

&lt;p&gt;When cryptographic keys are required on Android, the Android Keystore&lt;br&gt;
provides a platform mechanism for key management.&lt;/p&gt;

&lt;p&gt;Conceptually:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Application
     |
     v
Crypto Operation
     |
     v
Android Keystore
     |
     v
Protected Key Material
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The application can use the key for cryptographic operations without&lt;br&gt;
treating the key as an ordinary string that is freely passed around the&lt;br&gt;
application.&lt;/p&gt;

&lt;p&gt;For example, an application may generate a key:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="kd"&gt;val&lt;/span&gt; &lt;span class="py"&gt;keyGenerator&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;KeyGenerator&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;getInstance&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="nc"&gt;KeyProperties&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;KEY_ALGORITHM_AES&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s"&gt;"AndroidKeyStore"&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="n"&gt;keyGenerator&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;init&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="nc"&gt;KeyGenParameterSpec&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;Builder&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
        &lt;span class="s"&gt;"app_key"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
        &lt;span class="nc"&gt;KeyProperties&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;PURPOSE_ENCRYPT&lt;/span&gt; &lt;span class="n"&gt;or&lt;/span&gt;
            &lt;span class="nc"&gt;KeyProperties&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;PURPOSE_DECRYPT&lt;/span&gt;
    &lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;setBlockModes&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nc"&gt;KeyProperties&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;BLOCK_MODE_GCM&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;setEncryptionPaddings&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
            &lt;span class="nc"&gt;KeyProperties&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;ENCRYPTION_PADDING_NONE&lt;/span&gt;
        &lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;build&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;

&lt;span class="kd"&gt;val&lt;/span&gt; &lt;span class="py"&gt;secretKey&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;keyGenerator&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;generateKey&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The exact cryptographic configuration should be chosen according to the&lt;br&gt;
application's requirements.&lt;/p&gt;

&lt;p&gt;The important lesson is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Don't invent your own key-storage mechanism when the platform&lt;br&gt;
already provides one.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;


&lt;h2&gt;
  
  
  7. Encryption Alone Does Not Make an Application Secure
&lt;/h2&gt;

&lt;p&gt;Developers sometimes say:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"We use AES-256, so our data is secure."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That's incomplete.&lt;/p&gt;

&lt;p&gt;You also need to understand:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  How is the key generated?&lt;/li&gt;
&lt;li&gt;  Where is the key stored?&lt;/li&gt;
&lt;li&gt;  How is the key exchanged?&lt;/li&gt;
&lt;li&gt;  How is the key rotated?&lt;/li&gt;
&lt;li&gt;  What encryption mode is being used?&lt;/li&gt;
&lt;li&gt;  How are IVs/nonces generated?&lt;/li&gt;
&lt;li&gt;  How is integrity/authentication provided?&lt;/li&gt;
&lt;li&gt;  What happens if the key is compromised?&lt;/li&gt;
&lt;li&gt;  Can old data still be decrypted?&lt;/li&gt;
&lt;li&gt;  Is encryption being applied at the correct layer?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Data
 ↓
Encryption
 ↓
Storage
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;is only part of the design.&lt;/p&gt;

&lt;p&gt;You also need:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Key Management
       +
Access Control
       +
Integrity Protection
       +
Secure Storage
       +
Lifecycle Management
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Cryptography is a system, not simply an algorithm name.&lt;/p&gt;




&lt;h2&gt;
  
  
  8. Use Authenticated Encryption Where Appropriate
&lt;/h2&gt;

&lt;p&gt;When encrypting application data, confidentiality alone is not always&lt;br&gt;
enough.&lt;/p&gt;

&lt;p&gt;You generally also need protection against unauthorized modification.&lt;/p&gt;

&lt;p&gt;Conceptually:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Plaintext
    ↓
Encryption + Integrity Protection
    ↓
Ciphertext
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Authenticated encryption modes such as AES-GCM can provide&lt;br&gt;
confidentiality and integrity together when used correctly.&lt;/p&gt;

&lt;p&gt;Avoid designing your own encryption protocol.&lt;/p&gt;

&lt;p&gt;For example, don't create a custom encryption scheme without&lt;br&gt;
understanding the cryptographic requirements.&lt;/p&gt;

&lt;p&gt;A custom cryptographic design can introduce vulnerabilities even when&lt;br&gt;
the underlying algorithm is strong.&lt;/p&gt;


&lt;h2&gt;
  
  
  9. HTTPS Is Necessary --- But It Is Not Enough
&lt;/h2&gt;

&lt;p&gt;Sensitive application traffic should use secure transport.&lt;/p&gt;

&lt;p&gt;Instead of:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;http://api.example.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;production applications should use:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://api.example.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But HTTPS does not automatically make the API secure.&lt;/p&gt;

&lt;p&gt;Consider:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;POST /api/users/123/profile
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Even with HTTPS, the backend must still determine:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Is the user authenticated?
        ↓
Is the user authorized?
        ↓
Does the resource belong to the user?
        ↓
Is this operation allowed?
        ↓
Is the request valid?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;So think of security as layers:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;TLS
 ↓
Authentication
 ↓
Authorization
 ↓
Input Validation
 ↓
Business Rules
 ↓
Data Protection
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  10. Don't Disable TLS Verification to Fix Development Problems
&lt;/h2&gt;

&lt;p&gt;One of the most dangerous shortcuts is disabling certificate or hostname&lt;br&gt;
validation because a development server isn't configured correctly.&lt;/p&gt;

&lt;p&gt;Avoid production configurations that effectively say:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Accept any certificate
Accept any hostname
Trust everything
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This may make a development environment appear to work, but it removes&lt;br&gt;
important security guarantees.&lt;/p&gt;

&lt;p&gt;Instead:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Development Environment
        ↓
Proper Development Certificate

Production Environment
        ↓
Proper Production Certificate
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If your development environment uses self-signed certificates, configure&lt;br&gt;
development trust intentionally rather than disabling validation&lt;br&gt;
globally.&lt;/p&gt;


&lt;h2&gt;
  
  
  11. WebView Is an Important Attack Surface
&lt;/h2&gt;

&lt;p&gt;WebView is extremely useful for applications that need to display web&lt;br&gt;
content.&lt;/p&gt;

&lt;p&gt;But WebView also introduces additional security considerations.&lt;/p&gt;

&lt;p&gt;Potential areas include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  JavaScript&lt;/li&gt;
&lt;li&gt;  JavaScript interfaces&lt;/li&gt;
&lt;li&gt;  URL navigation&lt;/li&gt;
&lt;li&gt;  File access&lt;/li&gt;
&lt;li&gt;  Cookies&lt;/li&gt;
&lt;li&gt;  Redirects&lt;/li&gt;
&lt;li&gt;  Authentication&lt;/li&gt;
&lt;li&gt;  Local storage&lt;/li&gt;
&lt;li&gt;  External intents&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If your application only needs to display trusted content, don't give&lt;br&gt;
the WebView unnecessary capabilities.&lt;/p&gt;

&lt;p&gt;For example, avoid blindly loading arbitrary URLs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="n"&gt;webView&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;loadUrl&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;userProvidedUrl&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Instead, validate the URL before loading it.&lt;/p&gt;

&lt;p&gt;Conceptually:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Requested URL
      |
      ▼
Is domain trusted?
      |
 ┌────┴────┐
 YES       NO
  |         |
  ▼         ▼
WebView   Reject
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  12. JavaScript Interfaces Need Extra Care
&lt;/h2&gt;

&lt;p&gt;Android allows applications to expose native functionality to&lt;br&gt;
JavaScript.&lt;/p&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="n"&gt;webView&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;addJavascriptInterface&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;bridge&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="s"&gt;"AndroidBridge"&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This can be useful.&lt;/p&gt;

&lt;p&gt;But it also creates a bridge between web content and native application&lt;br&gt;
functionality.&lt;/p&gt;

&lt;p&gt;If untrusted content can interact with that bridge, the security impact&lt;br&gt;
can be significant.&lt;/p&gt;

&lt;p&gt;Before exposing a JavaScript interface, ask:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Who controls the loaded page?

Can an attacker influence the URL?

What methods are exposed?

What data can those methods access?

Can those methods perform privileged operations?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Only expose the minimum functionality required.&lt;/p&gt;




&lt;h2&gt;
  
  
  13. Deep Links Are Untrusted Input
&lt;/h2&gt;

&lt;p&gt;Deep links are convenient:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;myapp://article/123
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;or:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;https://example.com/article/123
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But the values coming from a deep link should be treated as untrusted&lt;br&gt;
input.&lt;/p&gt;

&lt;p&gt;Validate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Scheme&lt;/li&gt;
&lt;li&gt;  Host&lt;/li&gt;
&lt;li&gt;  Path&lt;/li&gt;
&lt;li&gt;  Parameters&lt;/li&gt;
&lt;li&gt;  Authentication state&lt;/li&gt;
&lt;li&gt;  Authorization&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Deep Link
    ↓
Parse
    ↓
Validate
    ↓
Authenticate
    ↓
Authorize
    ↓
Navigate
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Don't let a deep link directly perform a sensitive operation simply&lt;br&gt;
because the application was launched using a trusted-looking URL.&lt;/p&gt;


&lt;h2&gt;
  
  
  14. Validate Server Responses Too
&lt;/h2&gt;

&lt;p&gt;Security isn't only about validating input from users.&lt;/p&gt;

&lt;p&gt;Applications should also carefully process server responses.&lt;/p&gt;

&lt;p&gt;For example, don't assume that every response field will always contain&lt;br&gt;
the expected value.&lt;/p&gt;

&lt;p&gt;Instead of:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="kd"&gt;val&lt;/span&gt; &lt;span class="py"&gt;amount&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;response&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;amount&lt;/span&gt;&lt;span class="o"&gt;!!&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;consider appropriate validation and error handling.&lt;/p&gt;

&lt;p&gt;External systems can fail.&lt;/p&gt;

&lt;p&gt;Servers can be misconfigured.&lt;/p&gt;

&lt;p&gt;APIs can change.&lt;/p&gt;

&lt;p&gt;Attackers can manipulate requests.&lt;/p&gt;

&lt;p&gt;Defensive programming is an important part of application security.&lt;/p&gt;




&lt;h2&gt;
  
  
  15. Review Exported Android Components
&lt;/h2&gt;

&lt;p&gt;Android applications contain components such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Activities&lt;/li&gt;
&lt;li&gt;  Services&lt;/li&gt;
&lt;li&gt;  Broadcast Receivers&lt;/li&gt;
&lt;li&gt;  Content Providers&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For each component, ask:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Does this component need to be externally accessible?

Who can invoke it?

What input does it receive?

What permissions are required?

Does it expose sensitive functionality?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If a component doesn't need to be externally accessible, don't expose it&lt;br&gt;
unnecessarily.&lt;/p&gt;

&lt;p&gt;Security configuration should be intentional.&lt;/p&gt;


&lt;h2&gt;
  
  
  16. Be Careful With Broadcast Receivers
&lt;/h2&gt;

&lt;p&gt;Broadcast receivers can receive system or application broadcasts.&lt;/p&gt;

&lt;p&gt;If sensitive functionality is exposed through a receiver, carefully&lt;br&gt;
consider:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Who can send the broadcast?
What data does it contain?
Can another application trigger it?
Does it require permission?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A receiver that performs privileged actions should not blindly trust&lt;br&gt;
external broadcast data.&lt;/p&gt;


&lt;h2&gt;
  
  
  17. Don't Leak Sensitive Data Through Logs
&lt;/h2&gt;

&lt;p&gt;Logging is essential during development.&lt;/p&gt;

&lt;p&gt;But this is dangerous:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="nc"&gt;Log&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;d&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"AUTH"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"Access Token = $accessToken"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="nc"&gt;Log&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;d&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"USER"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"OTP = $otp"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="nc"&gt;Log&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;d&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"CRYPTO"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s"&gt;"Key = $key"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Avoid logging:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Access tokens&lt;/li&gt;
&lt;li&gt;  Refresh tokens&lt;/li&gt;
&lt;li&gt;  Passwords&lt;/li&gt;
&lt;li&gt;  OTP codes&lt;/li&gt;
&lt;li&gt;  Session IDs&lt;/li&gt;
&lt;li&gt;  Encryption keys&lt;/li&gt;
&lt;li&gt;  Personal information&lt;/li&gt;
&lt;li&gt;  Payment information&lt;/li&gt;
&lt;li&gt;  Sensitive API responses&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A useful rule is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;If an attacker could use the information in your logs, don't log&lt;br&gt;
it.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Also review logs before production release.&lt;/p&gt;




&lt;h2&gt;
  
  
  18. Be Careful With Screenshots and Sensitive UI
&lt;/h2&gt;

&lt;p&gt;Some applications display sensitive information:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Banking information&lt;/li&gt;
&lt;li&gt;  Payment details&lt;/li&gt;
&lt;li&gt;  OTP&lt;/li&gt;
&lt;li&gt;  Private messages&lt;/li&gt;
&lt;li&gt;  Documents&lt;/li&gt;
&lt;li&gt;  Medical information&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For particularly sensitive screens, consider whether screenshots or&lt;br&gt;
screen capture should be allowed.&lt;/p&gt;

&lt;p&gt;Android provides mechanisms such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="n"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;setFlags&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="nc"&gt;WindowManager&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;LayoutParams&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;FLAG_SECURE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="nc"&gt;WindowManager&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;LayoutParams&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nc"&gt;FLAG_SECURE&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But this should be applied based on actual requirements rather than&lt;br&gt;
blindly across the entire application.&lt;/p&gt;

&lt;p&gt;Security controls should match the sensitivity of the data.&lt;/p&gt;


&lt;h2&gt;
  
  
  19. Third-Party SDKs Are Part of Your Attack Surface
&lt;/h2&gt;

&lt;p&gt;Your application isn't composed only of your own code.&lt;/p&gt;

&lt;p&gt;A modern application might include:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Application Code
       +
Analytics SDK
       +
Crash Reporting
       +
Payment SDK
       +
Advertising SDK
       +
Networking Libraries
       +
Image Libraries
       +
Authentication SDK
       +
Build Plugins
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Every dependency introduces additional code and permissions.&lt;/p&gt;

&lt;p&gt;Regularly review:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Dependency versions&lt;/li&gt;
&lt;li&gt;  Transitive dependencies&lt;/li&gt;
&lt;li&gt;  Known vulnerabilities&lt;/li&gt;
&lt;li&gt;  SDK permissions&lt;/li&gt;
&lt;li&gt;  Network behavior&lt;/li&gt;
&lt;li&gt;  Data collection&lt;/li&gt;
&lt;li&gt;  Build plugins&lt;/li&gt;
&lt;li&gt;  Unused dependencies&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A useful mindset is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;If it ships inside my application, it is part of my attack&lt;br&gt;
surface.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  20. Secure the CI/CD Pipeline
&lt;/h2&gt;

&lt;p&gt;Security doesn't end when application development is complete.&lt;/p&gt;

&lt;p&gt;Consider the complete pipeline:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Developer
    ↓
Git Repository
    ↓
Pull Request
    ↓
CI/CD
    ↓
Dependencies
    ↓
Build
    ↓
Signing
    ↓
Release Artifact
    ↓
Distribution
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Every stage needs appropriate protection.&lt;/p&gt;

&lt;p&gt;Important areas include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Protected branches&lt;/li&gt;
&lt;li&gt;  Secret management&lt;/li&gt;
&lt;li&gt;  Dependency scanning&lt;/li&gt;
&lt;li&gt;  Secret scanning&lt;/li&gt;
&lt;li&gt;  Code review&lt;/li&gt;
&lt;li&gt;  CI/CD permissions&lt;/li&gt;
&lt;li&gt;  Signing key protection&lt;/li&gt;
&lt;li&gt;  Release access&lt;/li&gt;
&lt;li&gt;  Artifact integrity&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example, your signing credentials should never be committed to Git.&lt;/p&gt;

&lt;p&gt;Use secure secret management in your CI/CD environment.&lt;/p&gt;




&lt;h2&gt;
  
  
  21. Protect the Android Signing Key
&lt;/h2&gt;

&lt;p&gt;The signing key is extremely important.&lt;/p&gt;

&lt;p&gt;If an attacker gains access to your production signing credentials, the&lt;br&gt;
consequences can be serious.&lt;/p&gt;

&lt;p&gt;Therefore:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Signing Key
     ↓
Secure Storage
     ↓
Restricted Access
     ↓
Controlled CI/CD Usage
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Don't distribute the production keystore unnecessarily across developer&lt;br&gt;
machines.&lt;/p&gt;

&lt;p&gt;Keep access limited to the people and systems that actually need it.&lt;/p&gt;


&lt;h2&gt;
  
  
  22. Assume the APK Can Be Reverse-Engineered
&lt;/h2&gt;

&lt;p&gt;An APK is distributed to users.&lt;/p&gt;

&lt;p&gt;Therefore:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Assume that someone can inspect your application.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A possible attack path is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;APK
 ↓
Decompilation
 ↓
Resource Analysis
 ↓
Code Analysis
 ↓
Runtime Analysis
 ↓
Application Behavior
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;R8 can reduce and obfuscate application code:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="n"&gt;minifyEnabled&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="k"&gt;true&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But obfuscation is not a replacement for security.&lt;/p&gt;

&lt;p&gt;Don't depend on:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Obfuscation = Security
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Instead:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Secure Architecture
        +
Backend Authorization
        +
Secure Storage
        +
Cryptography
        +
Obfuscation
        +
Runtime Protections
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Each layer addresses a different problem.&lt;/p&gt;




&lt;h2&gt;
  
  
  23. Client-Side Security Checks Can Be Bypassed
&lt;/h2&gt;

&lt;p&gt;Consider:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight kotlin"&gt;&lt;code&gt;&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;isPremiumUser&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="nf"&gt;showPremiumFeature&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This controls the UI.&lt;/p&gt;

&lt;p&gt;It does not necessarily protect the feature.&lt;/p&gt;

&lt;p&gt;An attacker could potentially modify application behavior or directly&lt;br&gt;
call the backend.&lt;/p&gt;

&lt;p&gt;A secure architecture looks like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Android Client
      |
      | Request
      ▼
Backend
      |
      | Verify entitlement
      ▼
Allow / Reject
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The client can improve user experience.&lt;/p&gt;

&lt;p&gt;The backend should enforce business-critical security rules.&lt;/p&gt;




&lt;h2&gt;
  
  
  24. Don't Trust Client-Side Values
&lt;/h2&gt;

&lt;p&gt;Never blindly trust values such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  &lt;code&gt;isAdmin&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;isPremium&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;isVerified&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;isAuthenticated&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;userId&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;role&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;price&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;discount&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;  &lt;code&gt;permission&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example, this is dangerous:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"userId"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"123"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"isAdmin"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;if the server simply trusts whatever the client sends.&lt;/p&gt;

&lt;p&gt;Instead, security-sensitive properties should be determined and&lt;br&gt;
validated by trusted backend systems.&lt;/p&gt;


&lt;h2&gt;
  
  
  25. Input Validation Matters
&lt;/h2&gt;

&lt;p&gt;Anything coming from outside your trusted application boundary should be&lt;br&gt;
considered untrusted.&lt;/p&gt;

&lt;p&gt;Examples include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  User input&lt;/li&gt;
&lt;li&gt;  Deep links&lt;/li&gt;
&lt;li&gt;  Intent extras&lt;/li&gt;
&lt;li&gt;  Network responses&lt;/li&gt;
&lt;li&gt;  WebView URLs&lt;/li&gt;
&lt;li&gt;  Push notification data&lt;/li&gt;
&lt;li&gt;  Files&lt;/li&gt;
&lt;li&gt;  QR codes&lt;/li&gt;
&lt;li&gt;  Clipboard data&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Validate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Type&lt;/li&gt;
&lt;li&gt;  Length&lt;/li&gt;
&lt;li&gt;  Format&lt;/li&gt;
&lt;li&gt;  Range&lt;/li&gt;
&lt;li&gt;  Allowed characters&lt;/li&gt;
&lt;li&gt;  Business rules&lt;/li&gt;
&lt;li&gt;  Authorization&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For example, if an API expects:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;page = positive integer
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;don't blindly accept unexpected or excessively large values.&lt;/p&gt;

&lt;p&gt;Validation helps reduce both security issues and unexpected application&lt;br&gt;
behavior.&lt;/p&gt;


&lt;h2&gt;
  
  
  26. Handle Sensitive Errors Carefully
&lt;/h2&gt;

&lt;p&gt;Avoid exposing internal implementation details to users.&lt;/p&gt;

&lt;p&gt;Instead of:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;SQLException: connection failed at database server 10.0.0.4
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;show:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Something went wrong. Please try again.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Detailed information can be useful internally, but production users&lt;br&gt;
should generally receive appropriate, non-sensitive error messages.&lt;/p&gt;


&lt;h2&gt;
  
  
  27. App Integrity Should Be Part of the Threat Model
&lt;/h2&gt;

&lt;p&gt;For applications with higher security requirements, app-integrity&lt;br&gt;
mechanisms can provide additional signals about the application and&lt;br&gt;
environment.&lt;/p&gt;

&lt;p&gt;Conceptually:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Android Application
        |
        | Integrity Evidence
        ▼
     Backend
        |
        +-- Validate
        |
        +-- Evaluate Risk
        |
        +-- Enforce Policy
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The important principle is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Don't rely solely on a client-side boolean to determine whether the&lt;br&gt;
application is trustworthy.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;For sensitive operations, the backend should be able to enforce the&lt;br&gt;
security decision.&lt;/p&gt;


&lt;h2&gt;
  
  
  28. Security Testing Should Be Continuous
&lt;/h2&gt;

&lt;p&gt;Security testing shouldn't happen only before production release.&lt;/p&gt;

&lt;p&gt;A useful development lifecycle is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Design
  ↓
Threat Modeling
  ↓
Implementation
  ↓
Code Review
  ↓
Automated Security Checks
  ↓
Testing
  ↓
Release
  ↓
Monitoring
  ↓
Incident Response
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Consider testing:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  Authentication&lt;/li&gt;
&lt;li&gt;  Authorization&lt;/li&gt;
&lt;li&gt;  Local storage&lt;/li&gt;
&lt;li&gt;  Network communication&lt;/li&gt;
&lt;li&gt;  WebView&lt;/li&gt;
&lt;li&gt;  Deep links&lt;/li&gt;
&lt;li&gt;  Exported components&lt;/li&gt;
&lt;li&gt;  Cryptography&lt;/li&gt;
&lt;li&gt;  Dependencies&lt;/li&gt;
&lt;li&gt;  Release configuration&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The earlier a security problem is discovered, the easier it generally is&lt;br&gt;
to fix.&lt;/p&gt;


&lt;h2&gt;
  
  
  29. Threat Modeling Before Writing Code
&lt;/h2&gt;

&lt;p&gt;One of the most valuable security practices is threat modeling.&lt;/p&gt;

&lt;p&gt;Before implementing a feature, ask:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;What am I protecting?

Who might attack it?

What can the attacker control?

What happens if the attacker succeeds?

What security control reduces that risk?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Asset:
Authentication Token

Threat:
Token Theft

Attack Surface:
Local Storage
Logs
Network
Memory
Backup

Impact:
Account Takeover

Controls:
Secure Storage
TLS
Token Expiration
Token Rotation
Backend Validation
Logging Restrictions
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is much more useful than simply adding a security library because&lt;br&gt;
someone recommended it.&lt;/p&gt;


&lt;h1&gt;
  
  
  A Practical Android Security Checklist
&lt;/h1&gt;

&lt;p&gt;Before releasing an Android application, ask:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[ ] Are production secrets outside the APK?

[ ] Is authentication implemented securely?

[ ] Is authorization enforced by the backend?

[ ] Are access and refresh tokens protected?

[ ] Is sensitive local data protected?

[ ] Are cryptographic keys managed securely?

[ ] Is HTTPS configured correctly?

[ ] Is TLS verification enabled?

[ ] Are WebViews restricted?

[ ] Are JavaScript interfaces necessary and controlled?

[ ] Are deep links validated?

[ ] Are exported components intentional?

[ ] Are sensitive values excluded from logs?

[ ] Are screenshots restricted where necessary?

[ ] Have third-party dependencies been reviewed?

[ ] Are CI/CD secrets protected?

[ ] Are signing keys securely managed?

[ ] Has reverse engineering been considered?

[ ] Are client-side security checks backed by server-side enforcement?

[ ] Is user input validated?

[ ] Is the backend independently secure?

[ ] Are security tests part of the development lifecycle?

[ ] Has the application been threat-modeled?
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h1&gt;
  
  
  The Bigger Picture
&lt;/h1&gt;

&lt;p&gt;Android security isn't a single library.&lt;/p&gt;

&lt;p&gt;It isn't simply:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;AES
+
HTTPS
+
R8
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;A secure Android application requires multiple layers:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;                    Security
                       │
       ┌───────────────┼───────────────┐
       │               │               │
   Application      Platform        Backend
    Security        Security        Security
       │               │               │
       ├─ Auth         ├─ Keystore     ├─ Authorization
       ├─ WebView      ├─ Permissions  ├─ API Security
       ├─ Deep Links   ├─ Components   ├─ Rate Limiting
       ├─ Storage      ├─ IPC          ├─ Validation
       └─ Logging      └─ Integrity    └─ Monitoring
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The most important mindset shift is this:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Don't ask only, "How do I make my Android app secure?"&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Ask:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;"What happens if someone controls the device running my&lt;br&gt;
application?"&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That question changes the way you design authentication, APIs, storage,&lt;br&gt;
cryptography, WebViews, deep links, and even your CI/CD pipeline.&lt;/p&gt;

&lt;p&gt;Security should not be the final layer added to an Android application.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security should be one of the foundations on which the application is&lt;br&gt;
built.&lt;/strong&gt;&lt;/p&gt;


&lt;h1&gt;
  
  
  Final Thoughts
&lt;/h1&gt;

&lt;p&gt;As Android developers, we spend a lot of time thinking about:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;UI
Performance
Architecture
Networking
Database
Testing
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Security deserves the same level of attention.&lt;/p&gt;

&lt;p&gt;A production application should be designed with the assumption that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;  The client can be inspected.&lt;/li&gt;
&lt;li&gt;  User input can be manipulated.&lt;/li&gt;
&lt;li&gt;  Network requests can be replayed.&lt;/li&gt;
&lt;li&gt;  APK logic can be analyzed.&lt;/li&gt;
&lt;li&gt;  Dependencies can contain vulnerabilities.&lt;/li&gt;
&lt;li&gt;  Local data can be exposed on compromised devices.&lt;/li&gt;
&lt;li&gt;  Client-side checks can be bypassed.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal isn't to make an application impossible to attack.&lt;/p&gt;

&lt;p&gt;The goal is to make the architecture &lt;strong&gt;resistant, observable, and&lt;br&gt;
recoverable&lt;/strong&gt; when attacks happen.&lt;/p&gt;

&lt;p&gt;For developers who want to go deeper into mobile security, a good&lt;br&gt;
learning path is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Android Security Fundamentals
          ↓
Cryptography Basics
          ↓
Authentication &amp;amp; Authorization
          ↓
Secure Storage
          ↓
Network Security
          ↓
WebView &amp;amp; Deep Link Security
          ↓
Reverse Engineering
          ↓
Threat Modeling
          ↓
OWASP MASVS
          ↓
OWASP MASTG
          ↓
Mobile Security Testing
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The best security engineers don't just know how to use security APIs.&lt;/p&gt;

&lt;p&gt;They understand &lt;strong&gt;why the security control exists, what threat it&lt;br&gt;
addresses, and what happens when that control fails.&lt;/strong&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Secure coding is a development skill.\&lt;br&gt;
Security architecture is an engineering skill.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h1&gt;
  
  
  Android #Security #Kotlin #Cybersecurity
&lt;/h1&gt;




&lt;h2&gt;
  
  
  About the Author
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Padmakar Garg&lt;/strong&gt; is an Android Developer focused on Kotlin, Jetpack Compose, scalable application architecture, mobile security, and modern Android development. He writes about practical Android engineering, security, architecture, and real-world development challenges.&lt;/p&gt;

&lt;p&gt;Connect with me on DEV to follow more articles about &lt;strong&gt;Android development, Kotlin, Jetpack Compose, Android security, and mobile architecture&lt;/strong&gt;.&lt;/p&gt;

</description>
      <category>android</category>
      <category>security</category>
      <category>kotlin</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>I’m Joining the Kaggle Benchmarking Challenge 🚀 — Let’s Measure AI’s Weird Failure Modes</title>
      <dc:creator>Padmakar Android</dc:creator>
      <pubDate>Wed, 30 Sep 2026 06:11:31 +0000</pubDate>
      <link>https://dev.to/gargpadmakar/im-joining-the-kaggle-benchmarking-challenge-lets-measure-ais-weird-failure-modes-59c0</link>
      <guid>https://dev.to/gargpadmakar/im-joining-the-kaggle-benchmarking-challenge-lets-measure-ais-weird-failure-modes-59c0</guid>
      <description>&lt;h1&gt;
  
  
  I’m Joining the Kaggle Benchmarking Challenge 🚀
&lt;/h1&gt;

&lt;p&gt;AI models are getting better every day, but they still have some interesting—and sometimes unexpected—failure modes.&lt;/p&gt;

&lt;p&gt;That’s exactly what caught my attention about the &lt;strong&gt;Kaggle Benchmarking Challenge&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The challenge is focused on exploring unusual AI behavior through things like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;🧠 Multi-step reasoning&lt;/li&gt;
&lt;li&gt;💻 Code generation&lt;/li&gt;
&lt;li&gt;🔧 Tool usage&lt;/li&gt;
&lt;li&gt;🤖 Agentic workflows&lt;/li&gt;
&lt;li&gt;🔍 Other unexpected model behaviors&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal isn't just to build another benchmark.&lt;/p&gt;

&lt;p&gt;It's to identify a &lt;strong&gt;specific failure mode&lt;/strong&gt;, design a way to measure it, run experiments, and understand what the results tell us.&lt;/p&gt;

&lt;h2&gt;
  
  
  💡 My Approach
&lt;/h2&gt;

&lt;p&gt;As an Android developer, I'm particularly interested in how AI behaves when it has to work through multiple steps rather than simply generating a single response.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Can we reliably measure when an AI agent starts making mistakes as the number of reasoning/tool-use steps increases?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;I’m thinking about experimenting with:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Defining a reproducible task.&lt;/li&gt;
&lt;li&gt;Creating multiple levels of complexity.&lt;/li&gt;
&lt;li&gt;Running the same tasks across different scenarios.&lt;/li&gt;
&lt;li&gt;Measuring success and failure rates.&lt;/li&gt;
&lt;li&gt;Identifying patterns in the failures.&lt;/li&gt;
&lt;li&gt;Visualizing the results.&lt;/li&gt;
&lt;li&gt;Documenting what we learn.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  🔬 Why This Is Interesting
&lt;/h2&gt;

&lt;p&gt;Benchmarks usually focus on whether a model gets the answer right or wrong.&lt;/p&gt;

&lt;p&gt;But real-world AI systems are often more complicated.&lt;/p&gt;

&lt;p&gt;An agent might:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Choose the wrong tool.&lt;/li&gt;
&lt;li&gt;Use a tool incorrectly.&lt;/li&gt;
&lt;li&gt;Lose context during a multi-step task.&lt;/li&gt;
&lt;li&gt;Generate valid-looking but incorrect code.&lt;/li&gt;
&lt;li&gt;Make an error early in a workflow that causes later steps to fail.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These behaviors can be difficult to capture with traditional benchmarks.&lt;/p&gt;

&lt;p&gt;That's what makes this challenge interesting to me.&lt;/p&gt;

&lt;h2&gt;
  
  
  🚀 What I Hope to Learn
&lt;/h2&gt;

&lt;p&gt;My main goal isn't just to get a benchmark working.&lt;/p&gt;

&lt;p&gt;I want to understand:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Where does an AI system start to break down, and can we measure that breakdown consistently?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I'll be sharing the experiments, results, failures, and lessons learned along the way.&lt;/p&gt;

&lt;p&gt;If you're participating in the challenge too, I'd love to hear what failure modes you're exploring.&lt;/p&gt;

&lt;p&gt;Let's see what we can discover. 🔍&lt;/p&gt;

&lt;h1&gt;
  
  
  AI #MachineLearning #Kaggle #LLM #GenerativeAI #AIAgents #Benchmarking
&lt;/h1&gt;

</description>
      <category>ai</category>
      <category>machinelearning</category>
      <category>kaggle</category>
      <category>llm</category>
    </item>
  </channel>
</rss>
