A Bitcoin node syncs blocks and queries locally.
Organic Maps pulls tiles and queries locally.
Why can't Zapstore pull release bundles and query locally?
At first this sounded crazy.
It turns out it's (almost) the holy grail of privacy and UX.
Initial prototype of v2 is insanely promising.
App written in Kotlin from scratch.
Browsing apps is instant. Search is orders of magnitude better.
For update checks, no need to reveal your installed app set to any remote server.
Tor by default.
And that's just the tip of the iceberg.
More soon.
Zapstore
_@zapstore.dev
npub10r8x...t2p8
The open app store powered by your social network
Download 1.1.2 for Android: https://zapstore.dev/
SHA-256 checksum: 29b7aae256ef567e466c30fac13b8a7794d84a79862162d69f029f61c2ce5dd2
APK certificate hash (for AppVerifier): 99e33b0c2d07e75fcd9df7e40e886646ff667e3aa6648e1a1160b036cf2b9320
Support: https://zapstore.dev/community/forum
Nostr DMs will be ignored, tag us instead.
๐จ Please update to Zapstore 1.1.2
It was released last week and contains a fix for a major security bug found in an underlying library, related to nostr event verification.
I don't believe it has been exploited as apps are loaded primarily from relay.zapstore.dev (which properly verifies nostr events) and we haven't heard of any report.
Found by ethicnology, thank you Sir (couldn't find his nostr profile, he deserves some zaps!)

GitHub
GitHub - zapstore/zapstore: The open app store
The open app store. Contribute to zapstore/zapstore development by creating an account on GitHub.
Thank y'all for the kind words but also for the bug reports.
I hear you and know many things are suboptimal.
We are designing Zapstore v2 (mainly a new indexer with hard lessons learned, revamped zsp and a new mobile app)
I won't spill the beans yet but I'm excited. Everything starting to make much more sense.
๐ฏ


Seeing more Certificate Mismatch errors?
Deployed an upgrade to the indexer.
As we deprioritize F-Droid signed releases in favor of developer-signed (as it should be) you may find some new Certificate Mismatch errors.
To keep updating those apps you'll need to reinstall them. Unfortunately there is no other way. (If you have multiple profiles on your device, ensure to remove app from all of them!)
Apologies for the inconvenience, but it's the right move to minimize certificate mismatches in the future!
Someone is constantly releasing updates to an app.
It's cool too see how frictionless app publishing can be, on the other hand they live in Latest Releases which takes space away from other projects.
We're going to move away from this dumb REQ approach and work on a smarter feed for discovering new stuff.
Amazing charts of apps on Zapstore!


nostrolo.gy
The Zapstore app economy
Zapstore app publishing and zap activity measured end to end, from the Nozzl event archive.
GM developers
When publishing, don't skip linking your Android keystore/cert to your Nostr identity!
(We need to know that you actually own the app)
Soon, apps without it will show as unclaimed, as any other indexed app regardless of who published the app metadata.
๐ zsp release 0.4.14 :
- Fix bad name and icon extraction regression
- Fix Gitlab parser download path
- Add fastlane as metadata source
- Add Tor fallback for failing requests, retries
- Add default image compression

GitHub
GitHub - zapstore/zsp: Publish apps to relays
Publish apps to relays. Contribute to zapstore/zsp development by creating an account on GitHub.
NEW FEATURES
- Background auto updates (opt in)
- Check certificate ownership before installation
- Back up settings, bookmarks, and more to a device key
- Ability to exclude apps from updates
- NIP-56 reporting
- Shareable app dagnostics
- Efficient image loading
View quoted note โ
Also released new zsp and fixed several issues with apps stuck in the indexer.
Brave, Ironfox, Aurora Store, Flow and others are back!