| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
Full Android package control without the clutter.
AppManagerNG continues the App Manager project as a full-featured, root/ADB-aware package manager for Android. The interface focuses on clarity and approachability without sacrificing any of the depth that makes the original a power user staple.
Think of it as AppManager with a friendlier front door: the same engine, the same root/ADB capabilities, the same component blocking and tracker scanning, behind a Material 3 interface that doesn't punish casual users for opening it.
Note
AppManagerNG began as a rebranded baseline of the upstream AppManager source at commit 3d11bcb, bootstrapped on 2026-04-30. The NG UX overhaul has been landing incrementally since, in working increments, with attribution to upstream contributions preserved. See CHANGELOG.md for what each release changed.
Everything below is additive to the upstream feature set. The inherited capabilities are listed further down. For the release-by-release detail, see CHANGELOG.md.
Flips the standard "app → permissions" view on its head. Pick a permission group (Camera, Microphone, Location, Contacts, SMS, Phone, Files & media, Calendar, Body sensors, Physical activity, Nearby devices, Notifications) and see every installed app that holds it, with a one-tap toggle per app and a master Revoke for all apps action. Changes persist through the same rule store the per-app permissions tab uses, so they survive reinstalls.
Reclaim storage without losing anything: archiving removes an app's APK and cache but keeps its data and launcher icon, so unarchiving picks up where you left off. Drives the native Android 15 archiving API. Archive one app from App Info or many in a batch operation. Archived apps are detected and labelled in the app list. Works on user apps without root.
Profiles that run themselves. Schedule a profile, or trigger it on app install/update/uninstall with an optional package glob (com.vendor.*) so it fires only for the apps you care about. Backups gained ordered per-tag policies: the first matching tag decides which parts are backed up, how they are encrypted, how long they are kept, and whether they land locally or on a SAF destination. A preview shows which rule wins before you commit.
Query your device instead of scrolling it. Filter apps by trackers (including by class name or regex), permissions, app ops, signature, installer, SDK levels, size, usage, backup state, bloatware classification, intent actions, and domain links. Save the filter and reuse it. Native-library readiness is a predicate too: sweep for apps that are not 16 KB page-aligned (so they will not run on Android 15+ devices using 16 KB pages), ship only 32-bit code, or store their libraries compressed. App Details also reports each native library's ZIP data offset and whether its static symbols were stripped, so page alignment and packaging evidence stay visible together.
Export a portable, encrypted record of your app state, including rules, profiles, and preferences, then restore it selectively on another device, previewing each section before it is applied. Bundles are AES-256-GCM with an Argon2id-derived key, authenticated before anything is written, and streamed rather than held in memory, so a large bundle neither exhausts RAM nor half-applies.
Before an install commits, the prompt names the sensitive permissions the APK requests and the API levels it targets and supports, and reports the trackers it found. Installs that cannot fit are refused up front, with required-vs-free storage and a shortcut to the system storage manager. APK and OBB installation is rollback-safe: expansion files are staged and validated before the live ones are touched, so a failed install leaves the previous version intact.
Tracker and library results say what they are evidence of. An empty result reads "No known tracker matches" and explains why absence is not proof. Renamed identifiers, reflection, and runtime-loaded code all evade class-name matching. Each match is labelled confirmed or tentative and names the detector behind it, and exported reports carry the same provenance.
App Details explains Android's restricted-settings gate, which silently greys out accessibility, notification-listener, and health toggles for apps installed outside a store. It also explains how to lift it. Alongside it: privileged-mode capability detection (root, Shizuku, ADB, Dhizuku, KernelSU), an installer privilege cascade that falls back gracefully, and a biometric gate on the terminal and on backup deletion. When a privileged or destructive step cannot complete, the fallback stays conservative and the operation is recorded with enough context to diagnose the missing permission or service. App Details permission and error messages and file-manager starter names also come from resources, so those small interactions follow the selected locale. UID-scoped AppOps changes resolve every package sharing the UID before Android is allowed to mutate it. Shared and system UIDs require a reviewed batch plan that includes the complete effect. App Details shows the affected packages and operations inline when a single-app action is blocked. Internal package refresh signals stay inside AppManagerNG, reject malformed package lists before work starts, and reuse one bounded background worker.
Material 3 with dynamic colours and a pure-black theme, an onboarding capability wizard, a Pro Mode toggle that keeps advanced surfaces out of the way until you want them, global in-app Settings search, an in-app changelog viewer, and Quick Settings tiles for freeze and force-stop. The live Log Viewer also owns its reader for exactly as long as its view exists, so back navigation and rotation cannot deliver queued lines to an old screen.
Every release is built twice from a clean checkout and published only if both builds are byte-identical. A single fail-closed gate runs the tests, lint, version-consistency, and artifact-identity checks and emits a receipt binding the commit and tag to every artifact hash, the signing fingerprint, and the tool versions. A CycloneDX SBOM ships with each release, and the signing fingerprint is published at a stable URL for tools like AppVerifier. Release BUILD_TIME_MILLIS values come from SOURCE_DATE_EPOCH or the Git commit timestamp, and release builds fail when neither deterministic source is available. The release verifier also rebuilds the privileged server JARs from a second checkout path with different locale and timezone settings, then records both hash pairs. D8 receives those class inputs through response files, with the Windows launcher using Java directly so long checkout paths do not exceed the command-line limit. Shared map-backed list refreshes also compare values before dispatching payloads, so unchanged rows keep their existing binding state.
See ROADMAP.md for planned work, RESEARCH.md for the current research backing, and docs/roadmap/COMPLETED.md for completed or stale items. Maintainer-local historical archives are intentionally excluded from published checkouts; shipped work remains traceable through this changelog and Git history. Version targets:
Every AppManagerNG release ships two build flavors. Both are the same app; the only difference is whether the optional online features are compiled in.
| Flavor | For | Optional online features (VirusTotal, debloat-definition auto-updates, Settings → Privacy → "Use the Internet") |
|---|---|---|
| floss | F-Droid, IzzyOnDroid, reproducibility audits, anyone who wants a fully offline build | Removed at compile time. There is no setting to turn them on. Local networking (ADB-over-TCP, wireless pairing, the localhost privileged-server) still works. |
| full | GitHub Releases / Obtainium power users who want online scan reports and the debloat-definition auto-updater | Available, opt-in. Every online feature stays gated behind its existing user toggle and the master "Use the Internet" preference. Nothing reaches the network without you turning it on. |
floss is the default flavor in source; full is the optional variant. If you don't need VirusTotal or debloat-definition auto-updates, floss is the right choice. See docs/distribution/build-flavors.md for the maintainer contract.
Grab the APK from GitHub Releases, then pick full or floss using the table above. Each release ships one universal APK per flavor, carrying native libraries for armeabi-v7a, arm64-v8a, x86, and x86_64, so the same file installs on every supported device. Per-ABI split APKs are not currently published.
Obtainium is the recommended path for users who want automatic update checks straight from GitHub Releases without going through any store.
Install Obtainium.
Add App → paste the URL: https://github.com/SysAdminDoc/AppManagerNG
(Optional but recommended) Use the bundled config file for fully pre-tuned settings (correct ABI auto-detection, version regex, prerelease-skipping):
Obtainium will then auto-track every signed release published to this repo and notify you on update.
Tip
Pair Obtainium with AppVerifier so every Obtainium-fetched APK is checked against the published certificate fingerprint below before install.
ROM builders who pre-seed F-Droid repositories should ship both the F-Droid 2.0 JSON file and the legacy XML file during the migration window. Templates and placement notes live in docs/distribution/rom-fdroid-preseed.md.
Important
Brazil / Indonesia / Singapore / Thailand users: Google's Android Developer Verification program begins enforcement on certified devices in your region on 2026-09-30. After that date, AppManagerNG (like every other on-device installer) is subject to the platform verifier gate. AppManagerNG preserves verifier failure reasons in install results and can offer an ADB-mode retry when ADB is already reachable, because ADB installs remain exempt.
APK signing certificate SHA-256 fingerprint:
21:5F:B4:70:63:2E:A6:CD:59:A4:BA:AB:35:0A:9E:0B:99:AD:11:0F:DD:FA:F5:A9:EA:64:61:E5:D0:C2:38:6C
Verify with AppVerifier or:
apksigner verify --print-certs AppManagerNG-<version>.apk | grep SHA-256Before publishing, maintainers run one fail-closed local release gate, scripts/release_gate.py. It checks, in order, that the working tree is clean and matches the release tag, that every version-bearing surface agrees, that pinned dependencies have not drifted, that the translation report is internally consistent, that the host test suite passes, that no lint issue sits outside the baseline, that two clean builds produce byte-identical APKs, and that the built APK's package, version, SDK levels, and signing certificate are the ones the sources declare. A receipt binding the commit and tag to every artifact hash, the signing fingerprint, and the tool versions is written only after all of it passes. Details, including the two-build reproducibility check invoked by the gate, are in docs/distribution/reproducible-builds.md.
The translation stage parses only language-qualified values-* resources, excludes night/API/size qualifiers, rejects stale source keys, and applies the reviewed per-locale floors in scripts/translation-coverage-baseline.json. When a deliberate translation baseline changes, regenerate it with py -3.12 scripts/translation_quality.py --write-baseline and review the resulting diff.
The gate also runs OWASP Dependency-Check as a blocking stage (no unsuppressed CVSS 9.0+ findings), retaining the HTML/SARIF reports and their hash receipt alongside the SBOM and APK sidecars.
Note
In v0.6.7 that CVE stage could not run at all: dependencyCheckAggregate resolves configurations whose POMs were absent from gradle/verification-metadata.xml, so Gradle aborted it before the scanner started, and v0.6.7 shipped without CVE evidence. That was fixed in v0.6.8. the scanner runs to completion and writes its receipt.
The first complete run reported 12 findings above the CVSS 9.0 threshold. All twelve were assessed in v0.6.8 and dispositioned in config/owasp-suppressions.xml, each rule naming its CVE, the exact artifact family and version, and the reason it does not apply: androidx.sqlite matches the CPE of the upstream SQLite C library rather than the Java wrapper these artifacts ship (and no androidx/sqlite classes are present in the release DEX files); the io.netty artifacts come from the Android Gradle plugin's unified test platform and are never packaged into the APK; and the Kotlin findings are against build and toolchain jars that are likewise absent from the shipped application. No suppression is a blanket ignore. Dependency-Check reports a rule as unused once a scan stops seeing the matching finding, and the gate fails on that, so a disposition that stops being true becomes visible instead of silently persisting.
Untrusted app-list, rule, snapshot-manifest, and archive inputs also have a bounded local Jazzer gate. Run ./gradlew :app:fuzzUntrustedImports (or pass -PfuzzRuns=<count>); each target uses a fixed seed and a 64 KiB input ceiling. Crashes are written under app/build/fuzz-crashes/. Copy a minimized reproducer into the matching app/src/test/resources/fuzz-corpus/ directory so the normal unit suite retains it as a regression fixture.
Run scripts/verify-release-consistency.sh before release notes or APK publication to confirm the README badges, Fastlane changelog, Gradle wrapper, SDK pins, and local CLAUDE.md match the build metadata.
The same fingerprint is published in machine-parseable form at a stable URL so AppVerifier and similar tools can fetch it without scraping the README:
https://raw.githubusercontent.com/SysAdminDoc/AppManagerNG/main/docs/fingerprints.txt
The file is comment-tolerant (# prefix) and uses the same package: / sha256: record pairs as SD Maid SE's published fingerprints.
See BUILDING.rst. Submodules must be initialized before building:
git submodule update --init --recursiveSee CONTRIBUTING.md. Translation intake is planned, but the fork-owned Weblate/Crowdin project is not live yet.
Released under GPL-3.0-or-later. Per-file SPDX headers and the LICENSES/ directory follow the REUSE specification. Please preserve them.
See COPYING for the full GPL-3.0 text. Vendored third-party components retain their original licenses (Apache-2.0, BSD-2-Clause, BSD-3-Clause, CC-BY-SA-4.0, GPL-2.0, ISC, MIT, WTFPL) as documented in LICENSES/.
AppManagerNG would not exist without the years of work that went into the upstream App Manager project by Muntashir Al-Islam and the broader contributor community. AppManagerNG was bootstrapped from upstream commit 3d11bcb on 2026-04-30.
The original project remains the canonical implementation; AppManagerNG is a parallel effort focused on UX polish and approachability. If you want the upstream experience or want to contribute features broadly applicable to the package-manager domain, please direct your effort upstream first.
A full list of credits and bundled libraries is available in the About section of the app.
| Back | FazBrowse Home | New Git URL |