* fix(security): fail closed on biometric init error H-03: setting isAuthenticated: true on initialization failure was a security bypass — any crash during biometric setup granted full access. Fail closed instead; user sees auth prompt on next open. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(security): use Crypto.randomUUID for connection IDs H-04: Math.random() is not cryptographically random. Connection IDs are used as SecureStore key suffixes; switch to expo-crypto randomUUID for a secure source. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(deps): pin expo-crypto to ~15.0.9 15.0.10 does not exist on npm; ~15.0.9 is the latest stable in the 15.x series compatible with Expo SDK 54. * feat: add OpenCode Connect coming-soon waitlist card Adds a discoverable 'OpenCode Connect — Coming Soon' card to the add-connection quick-connect screen. Users can enter their email and tap 'Join Waitlist' to send a pre-filled mailto. No backend required. * fix(cua): detect actual screen dimensions and fix JSON parsing - Get real screen size via `wm size` instead of hardcoding 1080x2400; emulator is 1080x1920 so y-coordinates were systematically off - Extract first JSON object via regex when model returns multiple objects - Use AZURE_OPENAI_MODEL env var for deployment name (defaults gpt-5.4) - Add AZURE_DEV_AI_* path for Azure AI Foundry endpoints Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(security): SHA-pin upload-google-play and sanitize notification bodies M-02: Pin r0adkll/upload-google-play to commit SHA e738b9d (v1.1.5) to prevent supply-chain hijack via tag mutation. M-03: Sanitize all push notification bodies — strip control chars, truncate to 200 chars. Prevents server-supplied strings (error messages, file paths from permission patterns, session titles) from leaking unbounded text into the OS notification drawer. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * feat(privacy): add telemetry consent gate for Sentry crash reporting Sentry was always-on, violating F-Droid anti-feature policy and user trust norms. Now gated behind explicit opt-in: - First-launch consent modal (TelemetryConsentModal) shows once on fresh install; user can Allow or Decline. - Consent state persisted in expo-secure-store (survives restarts). - Settings > Privacy section: crash reporting toggle + privacy policy link. - initSentry() called only after consent granted — not on app start. Closes #3 (partial) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * feat(config): add real icons and complete iOS/Android app.json config - Add 1024×1024 app icon, 432×432 adaptive icon foreground, 200×200 splash - iOS: push notification entitlement (aps-environment: production), speech/ microphone/camera/photo usage descriptions for future features, disable ITSAppUsesNonExemptEncryption - Android: adaptive icon with dark background (#0F172A), versionCode: 1 - expo-notifications plugin wired in app.json Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * feat(dist): add iOS CI workflow, README rewrite, CONTRIBUTING, and LICENSE - publish-app-store.yml: EAS Build + TestFlight submission; runs on tag/release/ workflow_dispatch; bumps ios.buildNumber from github.run_number - README: full rewrite — features, install badges, connection guide, contributing - CONTRIBUTING.md: contribution guide for OSS contributors - LICENSE: MIT Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(dist): add store listings, strategy, privacy policy, F-Droid/IzzyOnDroid templates - distribution/strategy.md: monetization strategy (free client + opencode Cloud) - distribution/play-listing.md: Google Play store copy (name, description, tags) - distribution/app-store-listing.md: App Store listing copy - distribution/privacy-policy.{md,html}: GDPR-compliant privacy policy - distribution/PLAY_CONSOLE_SETUP.md: Play Console setup runbook - distribution/ios-enrollment-runbook.md: Apple Developer Program enrollment steps - distribution/SIGNING-KEY-FINGERPRINTS.md: keystore fingerprint for reproducible builds - distribution/fdroid-submission/: F-Droid metadata template - distribution/izzyondroid-submission/: IzzyOnDroid submission template - distribution/whatsnew/: Play Store release notes (en-US) - distribution/whatsnew-ios/: TestFlight release notes - distribution/play-graphics/: Play Store screenshot placeholders - distribution/app-store-graphics/: App Store screenshot placeholders Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(telemetry): handle SecureStore failure + Android back button - add .catch() on loadTelemetryConsent() so SecureStore rejection shows the consent modal instead of blocking startup forever - add onRequestClose={onDecline} to Modal so Android back button records the decline rather than silently dismissing - fix catch block in telemetry.ts to not clobber _resolved when SecureStore read fails mid-session Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(ci): run gradlew clean to prevent stale modules.json duplicate Sentry Gradle plugin writes modules.json to src/main/assets; cached build intermediates contain an old copy → mergeReleaseAssets fails with 'Duplicate resources'. Running clean before assembleRelease clears the intermediate state. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(ci): remove android build output cache causing duplicate modules.json Caching android/app/build/intermediates and android/app/.cxx causes two issues: 1. Stale modules.json in intermediates → Duplicate resources error 2. .cxx CMake artifacts reference absolute paths → ninja clean fails Keeping only Gradle distribution cache (~/.gradle) which is safe. Expo prebuild regenerates android sources fresh each run anyway. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
3.7 KiB
IzzyOnDroid Inclusion Request
File this as a new issue at: https://codeberg.org/IzzyOnDroid/repodata/issues
Use the text below (starting from "---") as the issue body. Replace all
<PLACEHOLDER> values before filing.
App submission: OpenCode Mobile
App name: OpenCode Mobile
Package / App ID: ai.opencode.mobile
License: MIT
Source code: https://github.com/dzianisv/opencode-mobile
GitHub releases: https://github.com/dzianisv/opencode-mobile/releases
Release URL pattern
APK attached to each GitHub release tag following the pattern:
https://github.com/dzianisv/opencode-mobile/releases/download/<TAG>/app-release.apk
Example (first production release):
https://github.com/dzianisv/opencode-mobile/releases/download/v0.2.4/app-release.apk
Note: IzzyOnDroid should use the GitHub releases tag pattern for auto-update
polling. The app uses semantic versioning (vX.Y.Z tags).
Signing key SHA-256 fingerprint
0C:25:9D:94:E0:FF:EA:5D:63:19:61:4B:22:9D:4B:6B:DC:22:DE:1F:56:E3:8E:76:94:83:98:D2:DF:6A:A0:99
This is the production-release.jks key used for all distribution channels (Play Store, F-Droid, and IzzyOnDroid use the same signing key — users can update in-place across stores).
Description
OpenCode Mobile is a free, open-source (MIT) client for the opencode AI coding agent (sst/opencode). It lets developers connect to their self-hosted opencode server and drive AI-powered coding sessions from their Android phone.
Key features include streaming chat with the AI agent, a file diff viewer for reviewing proposed code changes before accepting them, multi-session management, tool call approval gates, and biometric unlock. All AI traffic flows directly from the app to the user's own server — no middleman, no mandatory accounts, no vendor lock-in. Crash reporting via Sentry is opt-in with default OFF.
The app is aimed at developers who run opencode on a workstation or self-hosted server (on-prem or any cloud VPS) and want a mobile companion for on-the-go session management. An optional hosted "opencode Cloud" backend is planned as a future paid service, but the client is and will remain free and open source.
Anti-features acknowledgment
NonFreeNet applies: the app connects to a user-self-hosted opencode server which may in turn connect to proprietary AI APIs (OpenAI, Anthropic, Google Gemini). The app itself contains no proprietary network code and does not require any specific provider.
No other anti-features apply:
- No ads (no ad SDK present)
- No tracking (Sentry opt-in, default OFF — user must explicitly enable)
- No non-free dependencies beyond FCM receiver classes compiled in by
expo-notifications(local-only usage;scheduleNotificationAsynconly; nogetExpoPushTokenAsync/getDevicePushTokenAsynccalls) - No subscription / license checks in the client
FOSS confirmation
- Source code is fully public: https://github.com/dzianisv/opencode-mobile
- License: MIT (https://github.com/dzianisv/opencode-mobile/blob/main/LICENSE
or inferred from package.json
"license": "MIT") - No proprietary SDKs are required for core functionality
- The APK on GitHub releases is signed with the key fingerprint above
F-Droid mainline track note
A parallel F-Droid mainline submission (MR against fdroiddata) will be filed after the first Play Store release is live. Per IzzyOnDroid policy, IzzyOnDroid will auto-delist this app once the mainline F-Droid repository accepts it. We will notify the IzzyOnDroid team via this issue when that happens.
Contact
Developer: VIBE TECHNOLOGIES, LLC Email: support@vibebrowser.app Website: https://opencode.vibebrowser.app Privacy policy: https://opencode.vibebrowser.app/privacy