Can I get more info on why these are showing up? I’ve never seen such a thing on F-Droid before.

-18 points

Why is the F-Droid community on lemmy.ml??? (⁠●⁠´⁠⌓⁠`⁠●⁠)

permalink
report
reply
2 points

Maybe because lemmy.ml is “A community of privacy and FOSS enthusiasts, run by Lemmy’s developers.”

permalink
report
parent
reply
5 points

Your welcome to create a new one elsewhere

permalink
report
parent
reply
1 point

I would like to, but unfortunately I’m not experienced enough to do something like this.

permalink
report
parent
reply
1 point

You hit “create community”

It takes little time but shouldn’t be that crazy

permalink
report
parent
reply
32 points
*

The current version has a critical security vulnerability (https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/) but to fix it the new version compiled against libclang version 27 but Google decided to remove it from Android so the building pipeline needs to be adjusted.

There’s a long discussion: https://gitlab.com/relan/fennecbuild/-/merge_requests/63 , about building the newer version

In the meanwhile the app is a security hazard.

permalink
report
reply
9 points
*

Uninstalling my primary browser isn’t really a practical solution, what am I supposed to use, Chrome? How about fixing the version they’re shipping? Or should I be looking somewhere other than F-Droid for Android Firefox?

permalink
report
reply
1 point

Or should I be looking somewhere other than F-Droid for Android Firefox?

FFUpdater, on F-Droid, manages updates for Firefox and other browsers. I counted nine variations of Firefox or forks of Firefox. As well as eight variations of Chromium based browsers that aren’t Chrome. So that’s 17 options.

permalink
report
parent
reply
2 points

Iceraven is a Mozilla based standin.

Can install FFUpdater here:

https://f-droid.org/packages/de.marmaro.krt.ffupdater/

and then select it from there.

permalink
report
parent
reply
12 points
*

I changed to the Divest-repo for Mull, and they have an updated version that has fixed these security issues.

ETA: Different signing keys though, so you can’t just update it, but have to reinstall.

permalink
report
parent
reply
2 points

How do you do that?

permalink
report
parent
reply
4 points

You add https://divestos.org/apks/official/fdroid/repo/ as a repo in F-Droid settings. After that you can choose which repo to prefer for Mull.

permalink
report
parent
reply
2 points

I just install Firefox from the Play Store. 🤷‍♂️ Is that bad?

permalink
report
parent
reply
8 points

Yes

permalink
report
parent
reply
11 points

Theyre the distributor, the dont fix apps and its not their job to do so. Getting the same app from a different source wont change anything

permalink
report
parent
reply
5 points

huh? no one’s asking them to fix firefox, we’re asking that they just ship the latest version.

the warning states that several vulnerabilities have been fixed since firefox version 130, f-droid’s latest version of the package is 129: that very much makes it sound like the problem is wholly caused by f-droid not making version 130 available.

permalink
report
parent
reply
0 points

huh? no one’s asking them to fix firefox, we’re asking that they just ship the latest version.

Huh to your huh? What’s significant about the latest version, other than that it includes requested fixes? This is 12 of one, a dozen of the other.

permalink
report
parent
reply
6 points

To ship it they have to work out how to build that version themselves from source though - that’s their whole thing. It’s not like a normal app store where they take pre-built binaries from the developer.

permalink
report
parent
reply
2 points

Well ok if thats the case you are completely right, as long as there isnt some kind of issue and others have already updated the package pushing security fixes asap is indeod important

permalink
report
parent
reply
24 points
*

There should really be push notifications around installed apps with known vulns… Its tracked here: https://forum.f-droid.org/t/vulnerability-warnings-in-f-droid-app/20505

Could someone with a gitlab account open a feature request on the f droid repo?

I tried to open an account but it required email + cell phone (it picked up my VoIP number) and a credit card…

EDIT: I generated an RSS feed based off of Mozilla’s known vuln list. If anyone knows of a better way to do this, please let me know!

permalink
report
reply
44 points
*

There was a critical vulnerability found on Firefox some days ago: CVE-2024-9680. Fennec and Mull are forks of Firefox. They both fixed this issue already in their source code, BUT there is a problem preventing F-Droid from building these updated, fixed versions.

In the case of Mull, you can download the updated version from the DivestOS F-Droid repository: https://divestos.org/fdroid/official/, but if you are currently using the F-Droid version you will need to uninstall it first, since they have different signatures.

permalink
report
reply

F-Droid

!fdroid@lemmy.ml

Create post

F-Droid is an installable catalogue of FOSS (Free and Open Source Software) applications for the Android platform. The client makes it easy to browse, install, and keep track of updates on your device.

Website | GitLab | Mastodon

Matrix space | forum | IRC

Community stats

  • 512

    Monthly active users

  • 209

    Posts

  • 1K

    Comments