Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 1 addition & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,6 @@ jobs:
exit 1
fi
"$sdkmanager" "platforms;android-36" "build-tools;36.0.0"
- run: ruby scripts/test-play-release.rb
- run: bundle exec fastlane android checks
- name: Publish test and lint reports
if: always()
Expand All @@ -57,13 +56,12 @@ jobs:
name: message487-builds
path: |
app/build/outputs/apk/**/*.apk
app/build/outputs/bundle/**/*.aab
if-no-files-found: error
retention-days: 14
- name: Link build artifacts
env:
ARTIFACT_URL: ${{ steps.apk.outputs.artifact-url }}
run: echo "[Download debug APK and unsigned release APK/AAB]($ARTIFACT_URL)" >> "$GITHUB_STEP_SUMMARY"
run: echo "[Download debug APK and unsigned release APK]($ARTIFACT_URL)" >> "$GITHUB_STEP_SUMMARY"

python:
name: Python tests and style
Expand Down
38 changes: 0 additions & 38 deletions .github/workflows/play-metadata.yml

This file was deleted.

10 changes: 3 additions & 7 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ concurrency:

jobs:
release:
name: Build and verify signed APK and AAB
name: Build and verify signed APK
runs-on: ubuntu-latest
timeout-minutes: 40
steps:
Expand Down Expand Up @@ -80,7 +80,7 @@ jobs:
retention-days: 14

publish:
name: Publish GitHub Release and Google Play draft
name: Publish GitHub Release
needs: release
if: startsWith(github.ref, 'refs/tags/v') && github.event_name == 'push'
runs-on: ubuntu-latest
Expand All @@ -104,10 +104,6 @@ jobs:
run: |
cd dist/release
sha256sum -c SHA256SUMS
gh release create "$GITHUB_REF_NAME" ./*.apk ./*.aab mapping.txt SHA256SUMS \
gh release create "$GITHUB_REF_NAME" ./*.apk mapping.txt SHA256SUMS \
--repo "$GITHUB_REPOSITORY" --verify-tag --generate-notes \
--title "Message487 $GITHUB_REF_NAME"
- name: Upload Google Play internal draft
env:
SUPPLY_JSON_KEY_DATA: ${{ secrets.SUPPLY_JSON_KEY_DATA }}
run: bundle exec fastlane android play_release track:internal release_status:draft
23 changes: 22 additions & 1 deletion PRIVACY.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Privacy Policy

Last updated: September 28, 2026.
Last updated: October 5, 2026.

Message487 forwards selected notifications and new incoming SMS to a webhook you configure.
Its core SMS feature transfers new incoming SMS from Android to your n8n workflow so you can
Expand Down Expand Up @@ -79,6 +79,27 @@ Release builds require HTTPS. Debug builds also permit HTTP to the Android emula
localhost for development. The app contains no advertising, analytics SDKs or automatic crash
reporting, and does not automatically send data to the developer.

## App updates

The app determines an update source from Android's installer information and whether that
installer handles F-Droid repository links. An unknown installer requires a source choice.
A saved manual choice takes priority. This does not upload an installed-app inventory.

Update checks are enabled by default and run about once a day when a source is known and the
network is available. GitHub installs check the project's latest release through api.github.com;
F-Droid installs check f-droid.org. You can change the source or disable automatic checks in
App updates. These services receive the IP address and a Message487 update User-Agent; the app
does not include message contents, webhook credentials, device codes or installation IDs.

GitHub APK downloads require explicit consent and are stored in the app's update cache. The app
checks the release digest, package, increasing version code and matching installed signing
certificate before offering the system installer. Installation requires a separate user action
and Android's install permission. F-Droid updates open its app page and are handled by its client.
Notification permission is used only for update reminders. The source, automatic-check setting,
skipped versions and notification times are stored in private preferences without additional
encryption. Cached APKs can be removed by clearing the app cache; clearing app data removes
update preferences as well.

## Controls and deletion

To request deletion of a diagnostic report you sent to the Message487 developer:
Expand Down
13 changes: 9 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,12 +14,17 @@ A custom webhook is also supported. Telegram forwarding is one possible workflow
app does not depend on Telegram.

**Status:** development preview with notification/SMS capture, a persistent encrypted outbox,
background delivery, automatic retries and a delivery journal. Webhook requests require a Bearer token, stored encrypted on the device. Signed APK/AAB release automation is configured; see [Releases](docs/en/releases.md).
background delivery, automatic retries and a delivery journal. Webhook requests require a Bearer token, stored encrypted on the device. Signed APK release automation is configured; see [Releases](docs/en/releases.md).

## Getting started

**[Download the latest signed APK](https://github.com/andre487/AndroidMessage487/releases/latest/download/message487.apk)**

Message487 is also available from [F-Droid](https://f-droid.org/packages/life.andre.message487/).
Open **App updates** using the update icon in the top bar. The source follows the installer:
F-Droid clients use F-Droid, other named installers use GitHub. Unknown installers require a
manual choice. Daily checks can be disabled; downloads and installation require separate actions.

The stable link follows the latest published release; it does not point to development builds.
Read the [release notes](https://github.com/andre487/AndroidMessage487/releases/latest) for supported features.
Release 0.0.1 predates Bearer authentication.
Expand Down Expand Up @@ -119,10 +124,10 @@ bottom navigation on phones and rail navigation on wider windows. See the [desig
for the visual conventions and references.

Fastlane's `debug_artifact` lane builds only the debug APK. `checks` runs JVM/Robolectric tests,
debug/release lint, and builds debug and unsigned release APKs under `app/build/outputs/apk/`, plus an unsigned AAB under
`app/build/outputs/bundle/`.
debug/release lint, and builds debug and unsigned release APKs under `app/build/outputs/apk/`.

PR CI has no release signing credentials and does not require an emulator.
For signed APK/AAB artifacts and manual Play Console upload, see [Releases](docs/en/releases.md).
For signed APK releases, see [Releases](docs/en/releases.md).
Store graphics and their provenance are documented in [Branding](assets/branding/README.md).

See the [project context](docs/en/project-context.md) for remaining product decisions.
Expand Down
20 changes: 19 additions & 1 deletion app/src/main/AndroidManifest.xml
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,23 @@
<uses-permission android:name="android.permission.INTERNET" />
<uses-permission android:name="android.permission.ACCESS_NETWORK_STATE" />
<uses-permission android:name="android.permission.RECEIVE_SMS" />
<uses-permission android:name="android.permission.POST_NOTIFICATIONS" />
<uses-permission android:name="android.permission.RECEIVE_BOOT_COMPLETED" />
<uses-permission android:name="android.permission.REQUEST_INSTALL_PACKAGES" />
<uses-feature android:name="android.hardware.telephony" android:required="false" />
<queries>
<package android:name="org.fdroid.fdroid" />
<package android:name="org.fdroid.fdroid.privileged" />
<intent>
<action android:name="android.intent.action.VIEW" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="fdroidrepo" />
</intent>
<intent>
<action android:name="android.intent.action.VIEW" />
<category android:name="android.intent.category.BROWSABLE" />
<data android:scheme="fdroidrepos" />
</intent>
<intent>
<action android:name="android.intent.action.SENDTO" />
<data android:scheme="mailto" />
Expand Down Expand Up @@ -47,7 +62,10 @@
<action android:name="android.provider.Telephony.SMS_RECEIVED" />
</intent-filter>
</receiver>
<activity android:name=".MainActivity" android:exported="true">
<receiver android:name=".UpdateActionReceiver" android:exported="false" />
<service android:name=".UpdateCheckService"
android:permission="android.permission.BIND_JOB_SERVICE" android:exported="true" />
<activity android:name=".MainActivity" android:exported="true" android:launchMode="singleTop">
<intent-filter>
<action android:name="android.intent.action.MAIN" />
<category android:name="android.intent.category.LAUNCHER" />
Expand Down
Loading
Loading