ShizuStore

Aurora Droid

AuroraOSS

2.0.1 · GitLab

Download APK
Installer & app stores Android 7.0+ 1 month ago GPL-3.0
349 ShizuStore
363 Stars
8 MB Size

More about this app

FOSS F-Droid client with silent installs via Shizuku/root and automatic updates

Aurora Logo
GPL v3 Logo

Aurora Droid

Aurora Droid is another FOSS client for F-Droid.

It works with the same repositories as the official client and presents them through a Material 3 interface. Enable as many repositories as you like, and everything available to you appears in a single searchable catalogue. Downloads are handled by a proper download manager, installs can run silently through root or Shizuku, and updates can be checked and applied on their own.

Version 2.x is a full rewrite: new interface, new database, and new sync, download and install paths. Nothing carries over from 1.x, so repositories, favourites and blacklists have to be set up again.

Aurora Droid is not affiliated with or endorsed by F-Droid.

Get it on F-Droid

Nightly builds are at AuroraOSS and in the Telegram group.

Screenshots

Features

One catalogue across every repository. Apps from all enabled repositories appear in a single list, organised by category, with recently added and recently updated sections. Search covers all of them at once.

Repository management. Add any F-Droid repository by pasting its link, then enable, disable, reorder or remove it at any time. Where two repositories carry the same app, the one placed higher in the list takes precedence. F-Droid is enabled by default; IzzyOnDroid and microG are included but switched off.

Four install methods. The default session installer, the system installer, root, and Shizuku. Root and Shizuku install without a confirmation dialog for each app.

Scheduled update checks. Repositories are checked on an interval of your choosing, from every 6 hours to weekly, or not at all. On devices that support silent installs, updates can be downloaded and applied automatically. All background activity can be restricted to Wi-Fi.

Compatible updates only. Versions built for a different CPU architecture, or requiring a newer Android release than the device runs, are not offered as updates.

A full download manager. Progress, cancellation, retries and queue management, with automatic fallback to a repository's mirrors when its primary server is unavailable.

Grouped notifications. A batch of updates produces a single summary rather than one notification per app.

Favourites, blacklist and ignored updates. Mark the apps you follow, hide packages you never want to see, and skip a specific version of an individual app.

No tracking. No analytics, no accounts, no third-party services. Every APK is verified against the checksum published by its repository before installation, and repositories are pinned to their signing key, so a substituted server cannot serve different content.

Free software. GPLv3, developed in the open, with no proprietary components in the build.

Requirements

Requirement Version
Android 7.0 (API 24) and above
Target/compile SDK 37
JDK 21 (the Gradle toolchain resolves it automatically)
Gradle via ./gradlew, AGP 9.x, Kotlin 2.4.x

Building

git clone https://gitlab.com/AuroraOSS/auroradroid.git
cd auroradroid
./gradlew assembleDebug

The APK lands in app/build/outputs/apk/ as AuroraDroid-<version><-type><-unsigned>.apk.

Build types

Type Application ID Notes
debug com.aurora.adroid.debug Signed with the tracked AOSP testkey.jks, so debug builds are interchangeable across machines
release com.aurora.adroid Minified and resource-shrunk
nightly com.aurora.adroid.nightly Release settings, version name suffixed with the short commit hash

Release and nightly builds are signed only if a signing.properties exists in the project root; without it they are produced unsigned and the file name says so. The file is gitignored and looks like this:

STORE_FILE=/path/to/keystore.jks
STORE_PASSWORD=...
KEY_ALIAS=...
KEY_PASSWORD=...

Checks

./gradlew ktlintCheck    # style, `ktlintFormat` to fix
./gradlew lintDebug      # Android lint, config in app/lint.xml

Room schemas are exported to app/schemas/; commit the new JSON whenever the database version changes.

Project layout

Everything lives in the single :app module, under com.aurora.adroid.

Package What is in it
compose/ui/ One package per screen (apps, categories, updates, details, downloads, repositories, search, settings, about, installed, favourites, blacklist, ignored)
compose/composable/ Shared widgets: list items, top bars, placeholders, shimmer, permission lists
compose/navigation/ Screen keys and the Navigation 3 NavDisplay
compose/theme/ Material 3 expressive theme, dynamic colour, light/dark
viewmodel/ One ViewModel per screen, Paging 3 where lists can grow
data/sync/ Repository index: download, fingerprint verification, streaming parse, v2 diff merge, persistence
data/network/ OkHttp client, conditional index downloads, byte-range aware downloader, proxy support
data/download/ Mirror resolution and APK hash verification
data/installer/ Session, native, root and Shizuku installers behind one IInstaller
data/work/ SyncWorker, DownloadWorker, InstallWorker, UpdateWorker
data/room/ Database, DAOs and entities (repo, app, version, installed, download, favourite, blacklist, ignored, anti-feature)
data/repository/ Query surface the ViewModels talk to
data/helper/ Sync, download and install orchestration, update batching
data/receiver/ Install status, package add/remove, download cancel and retry
util/, extensions/ Preferences (DataStore), notifications, paths, shortcuts, small Kotlin/Android extensions

How a sync works

  1. SyncWorker runs per repository, either on demand or from a scheduled UpdateWorker sweep.
  2. RepoSyncer tries EntrySyncable first. It fetches entry.jar conditionally, so an unchanged repository costs one 304 response. Where the entry offers a diff against the timestamp already held, only the diff is fetched and merged as an RFC 7386 JSON merge patch.
  3. A 404 on entry.jar falls back to V1Syncable and index-v1.jar, which is converted to the v2 shape in memory.
  4. The JAR's signing certificate is hashed and matched against the repository fingerprint. A repository added without a fingerprint pins the one it presents on first sync; a mismatch after that fails the sync.
  5. IndexPersister streams the index into Room in a single transaction, so a failure part-way leaves the previous catalogue intact.

How an install works

DownloadWorker resolves the APK URL (falling back through the repository's mirrors), downloads it to filesDir/apk/, and verifies the SHA-256 from the index. InstallWorker then hands the file to the selected installer. Downloaded APKs are removed once the package manager confirms the install.

How to

Add a repository. More → Repositories → the add button. Paste either a plain URL or a full F-Droid link carrying the fingerprint, for example https://example.org/fdroid/repo?fingerprint=ABCD.... fdroidrepo:// and fdroidrepos:// links are accepted too. Without a fingerprint the first sync pins whatever the repository presents, which is trust-on-first-use, so prefer the fingerprint form when you have it.

Aurora Droid ships with F-Droid enabled, and IzzyOnDroid and microG present but disabled.

Reorder repositories. Drag them in the repositories list. The one nearer the top wins when the same package is published by more than one repo.

Install without confirming every app. Settings → App installer, then pick Root or Shizuku. Session and System both go through Android's own confirmation dialog and cannot be silent. Shizuku takes a little setup, covered below.

Turn on automatic updates. Settings → Updates → Install updates automatically. It stays paused unless background checks are on and the selected installer can install without confirmation, and the screen tells you which of the two is missing.

Change how often updates are checked. Settings → Updates → Update checks: never, every 6 hours, every 12 hours, daily or weekly. "Check on Wi-Fi only" makes background checks and automatic downloads wait for an unmetered network.

Use a proxy. Settings → Network → Proxy, as protocol://host:port with an optional user:password@. http, https, socks and socks5 are supported, and it takes effect on the next connection.

Stop an app from nagging. Open the app and ignore the update to skip that one version, or use the blacklist to hide the package entirely. Both lists are under More.

Setting up the Shizuku installer

Shizuku lends Aurora Droid the system privileges it needs to install apps without a confirmation dialog, on a device with no root. It is what makes fully automatic updates possible on a stock phone.

You need Android 8.0 or later.

1. Install and start Shizuku.

Get it from F-Droid or the project site, open it, and start the service by whichever route your device allows:

  • Wireless debugging (Android 11 and later, no computer needed) - turn on Developer options, enable Wireless debugging, and follow the pairing steps Shizuku walks you through.
  • ADB from a computer - enable USB debugging, plug in, and run the command Shizuku shows you.
  • Root - tap Start, grant superuser access, and you are done. If you are rooted, installing Sui instead is smoother; Aurora Droid treats it exactly like Shizuku.

Started over ADB or wireless debugging, Shizuku stops at every reboot and has to be started again. Started with root or Sui, it comes back on its own.

2. Point Aurora Droid at it.

Settings → App installer → Shizuku installer.

3. Grant the permission.

The first install asks Shizuku for access; allow it. If you miss the prompt, or something is off later, Aurora Droid tells you which piece is missing rather than failing quietly.

4. Optional: let updates install themselves.

With Shizuku working, Settings → Updates → Install updates automatically stops being greyed out. Pair it with an update check interval and new versions download and install in the background.

If installs start failing, the usual cause is Shizuku having stopped after a reboot. Open it and start the service again.

Translations

Aurora Droid is translated on Weblate: hosted.weblate.org/translate/aurora-droid.

Translation status per language

Adding a language or correcting a string needs no Git knowledge and no local setup; sign in and start typing. Source strings live in app/src/main/res/values/strings.xml and are the only ones edited by hand. Translated resources come back from Weblate, so please do not submit them as merge requests.

Credits

Aurora Droid reuses code from these projects, all GPL-3.0-or-later. Individual files carry the attribution in their header.

  • Aurora Store - installers (session, native, root, Shizuku), the download worker and download UI, notifications, navigation scaffolding, the settings screens and a number of shared composables.
  • Droid-ify - the repository sync path: index entry and v1 handling, JAR fingerprint verification, and the OkHttp download layer.
  • Neo Store - applying index-v2 diffs as RFC 7386 JSON merge patches.
  • F-Droid - the repositories, the index format and the specification everything above implements.

Libraries

Jetpack Compose · Material 3 · Navigation 3 · Room · Hilt · WorkManager · Paging 3 · DataStore · kotlinx.serialization · Coil · OkHttp · libsu · Shizuku · Refine · HiddenApiBypass

Support development

Bitcoin address Bitcoin Cash address Ethereum address BHIM UPI ID

Links

License

GPL-3.0-or-later. See LICENSE.

Close

How Shizuku is used

Can silently install apps via `IPackageInstaller` sessions through Shizuku

This is an AI-assisted analysis of Shizuku-related usages in the app's public source code. It is best effort, so it may not catch every single usage.

How this app uses Shizuku

Aurora Droid uses Shizuku to handle app installs without system confirmation dialogs once the user has chosen Shizuku as the installer.

  • Install apps silently: downloaded APK files are written to a system install session and committed in the background through the privileged package service via Shizuku, so installs and updates complete without tapping through prompts.
  • Cancel and clean up installs: in progress installs can be stopped by abandoning their install session through Shizuku, and leftover or orphaned sessions that cannot be removed normally are retried through the same privileged path.

Android APIs or commands used

  • IPackageManager
  • IPackageInstaller.createSession
  • IPackageInstaller.openSession
  • IPackageInstaller.abandonSession
  • IPackageInstallerSession
  • PackageInstaller.Session.commit
  • PackageInstaller.Session.abandon
  • PackageManager.INSTALL_REPLACE_EXISTING

Notable details

If Shizuku is unavailable the app falls back to its normal session installer or system install prompt, so installs still work with user confirmation.

Close

Changelog

What's new for version 2.0.1

Changelog : v2.0.1

* Rewritten from scratch, the UI is now Jetpack Compose and Material 3
* New install methods: session, native, root and Shizuku
* Repository sync, downloads and update checks now run as background work
* Reworked notifications, with grouped summaries for batch updates
* Reworked update checks & more

AuroraDroid-2.0.1.apk

Close

Permissions

13 permissions requested

  • android.permission.INTERNET
  • android.permission.ACCESS_NETWORK_STATE
  • android.permission.POST_NOTIFICATIONS
  • android.permission.FOREGROUND_SERVICE
  • android.permission.FOREGROUND_SERVICE_DATA_SYNC
  • android.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONS
  • android.permission.QUERY_ALL_PACKAGES
  • android.permission.REQUEST_INSTALL_PACKAGES
  • android.permission.REQUEST_DELETE_PACKAGES
  • android.permission.WAKE_LOCK
  • android.permission.RECEIVE_BOOT_COMPLETED
  • com.aurora.adroid.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION
  • moe.shizuku.manager.permission.API_V23
Close

Sources

3 sources

2.0.1 Universal GitLab · com.aurora.adroid
Selected Download
2.0.1 F-Droid · com.aurora.adroid · com.aurora.adroid
Download
2.0.1 arm64-v8a,armeabi-v7a,x86,x86_64 F-Droid · com.aurora.adroid · com.aurora.adroid
Download