Open-source project
komi-store/komi-store avatar
komi-store/komi-store

Komi Store: a cross-platform storefront for GitHub, Codeberg and Forgejo releases

🩵 A free, open-source app store for developers' releases on GitHub, Codeberg & Forgejo — browse, discover, and install apps with one click. Formerly GitHub Store.

18,904 stars713 forksKotlinApache-2.0

At a glance

What is it?
Komi Store is a Kotlin Multiplatform desktop and Android client that browses third-party release assets and installs them in one click. It is a discovery layer over repositories you already trust, not a review board.
Who is it for?
Adopt Komi Store if you already follow specific open-source projects and want their release assets in one browsable place on Android, Windows, macOS or Linux, and verify two things before you rely on it: the SHA-256 signing certificate B7:F2:8E:19:8E:48:C1:93:B0:38:C6:5D:92:DD:F7:BC:07:7B:0D:B5:9E:BC:9B:25:0A:6D:AC:48:C1:18:03:CA printed in the README, and the release page behind every download, because the project's own disclaimer says the contents, safety and behaviour of those downloads are the responsibility of their authors, not of Komi Store.
Can I use it commercially?
Yes. Apache-2.0 is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly Kotlin, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The gap between a GitHub release page and a usable install flow

Open-source releases live in a place built for reading, not for installing. A release page gives you a changelog, a wall of assets with names like app-1.9.2-arm64.dmg, and no indication of which file matches your machine. Komi Store's stated purpose is to fix that asymmetry: it is described as a cross-platform app store for GitHub releases, designed to simplify discovering and installing open-source software. The audience is developers and technical users who already know which projects they want, but would rather not repeat the download-and-check dance on every update. The repository topics point at the same audience: android, desktop, kotlin-multiplatform, linux, macos, windows. One detail matters more than the feature list. The README's disclaimer says Komi Store only helps you discover and download release assets already published on GitHub by third-party developers, and that it does not review, validate or guarantee that any installer is safe. Treat the app as a client, not a curator.

How Komi Store turns a repository list into an installable catalogue

The architecture is visible in the repository layout. composeApp, core and feature are the three source directories at the top level, alongside build-logic, packaging and dist. That split is the standard Kotlin Multiplatform shape: shared logic in core, per-capability modules under feature, and a Compose UI layer that targets Android and desktop from one codebase. The consequence is a single install pipeline for every platform rather than four separate implementations. What the README adds is a download mirror system listed among the features, which implies asset downloads can be routed through an alternative host when the direct GitHub URL is slow or blocked. The README does not document how mirrors are selected, how many exist, or what happens when one fails, so the failover behaviour is something you would have to observe rather than read. Two other features in the list, Smart discovery and Recently Released, are the discovery half: they surface projects you did not search for, using release activity as the signal. The README gives no ranking criteria for either.

Installing Komi Store on Windows, macOS, Android and Linux

The README routes each platform to its own package manager, and the commands below are copied from it. On Windows with Scoop, add the project's bucket and then install from it:

powershell
scoop bucket add komi-store https://github.com/komi-store/komi-store-scoop-bucket
scoop install komi-store/komi-store

WinGet users install the same app under its older package identifier, zed.rainxch.githubstore, which is a leftover from the GitHub Store name:

powershell
winget install zed.rainxch.githubstore

On macOS the README points to Homebrew and gives the tap and cask:

bash
brew tap komi-store/komi-store
brew install --cask komi-store

The README warns that macOS users may see a warning that Apple cannot verify Komi Store, because it is distributed outside the App Store and is not notarized yet, and instructs you to allow it through System Settings, Privacy & Security, Open Anyway. On Android the README links the GitHub releases page and F-Droid (package zed.rainxch.githubstore), and it publishes the APK signing certificate SHA-256 as B7:F2:8E:19:8E:48:C1:93:B0:38:C6:5D:92:DD:F7:BC:07:7B:0D:B5:9E:BC:9B:25:0A:6D:AC:48:C1:18:03:CA. Compare that fingerprint against the certificate your device reports before trusting an APK. Linux is listed as a topic and a supported desktop target, but the README's download section names no Linux-specific package manager, so you would start from the releases page.

The first real use: browsing a release and installing it

Once Komi Store is open, the flow follows the features the README lists. Recently Released gives you a feed of projects with fresh releases. Selecting one opens the rich details screen, which is where the release browser lives. That screen is the part that earns its keep: it lists the assets attached to a release and lets you install one without leaving the app. App management then tracks what you installed, and Collections lets you group projects rather than leaving them in a flat history. The README does not describe the exact controls on the details screen, so expect to learn the layout by using it. One thing to settle before you install anything: the app is a downloader. Whatever you click is fetched from the developer's own release and run on your machine, and the disclaimer places that risk on you.

Where Komi Store stops being the right tool

The limitation is structural, not a bug. Komi Store does not review, validate or guarantee that any installer is safe, free of malware or fit for any particular purpose, per its own disclaimer. That means it inherits every supply-chain problem of the releases it indexes, and it cannot warn you about a compromised maintainer account or a malicious asset added to a legitimate release. If your threat model requires a human review before software reaches your machine, Komi Store adds a step rather than removing one. A second constraint is scope: it indexes releases, so projects that ship only through a package registry, a container image or a source tarball without a release asset are invisible to it. Third, macOS installs arrive unnotarized, which the README acknowledges, and that warning will reappear for users who are not comfortable changing Privacy & Security settings. Finally, the README does not document rollback. App management is described as a feature, but nothing in the README states whether uninstalling or reverting to a previous version is handled from inside the app.

Komi Store against F-Droid and plain package managers

The nearest alternative is F-Droid, which the README itself links as an install channel for the Android build. The difference in approach is the source of truth. F-Droid builds applications from source in its own infrastructure and signs the results with its own key, which is why its catalogue is small and its update cadence is slow. Komi Store does the opposite: it points at whatever binary a developer published on GitHub, Codeberg or Forgejo, so coverage is wider and freshness is immediate, but the trust anchor is the upstream developer rather than a build farm. On desktop the comparison is Homebrew, Scoop and WinGet, which Komi Store partly sits on top of. Those tools install from curated manifests maintained by their own communities; Komi Store is a GUI over release assets, and its WinGet and Homebrew entries exist because someone packaged the app itself, not because it replaces them. If you want a vetted catalogue, use F-Droid or your platform's package manager. If you want the release a developer published an hour ago, Komi Store is the shorter path.

Maintenance, licensing and what an upgrade costs you

The repository is not archived, and the last push was on 2026-09-04. The release history shows the project renaming itself twice in a short window: v1.9.0 shipped as GitHub Store 1.9 on 2026-05-27, v1.9.1 announced the rename to Komi Store on 2026-06-11, and v1.9.2 followed on 2026-06-26. The rename has a practical cost that outlives the announcement. The Android and WinGet package identifier is still zed.rainxch.githubstore, and the F-Droid package is zed.rainxch.githubstore as well, so anything you scripted against the old identity keeps working while the user-facing name does not match. Upgrades themselves are cheap on the platforms with package managers: brew upgrade --cask komi-store, scoop update komi-store, or winget upgrade zed.rainxch.githubstore. On Android, updates come from the releases page or F-Droid, which means the signing certificate is the thing to keep stable across versions. The licence is Apache-2.0, which permits commercial use, modification and redistribution provided the licence and notices are preserved; the README also states the project is open to partnerships, sponsorships and integrations with a contact address, which is a separate commercial arrangement from the code licence. Nothing here is legal advice.

Editorial conclusion

Adopt Komi Store if you already follow specific open-source projects and want their release assets in one browsable place on Android, Windows, macOS or Linux, and verify two things before you rely on it: the SHA-256 signing certificate B7:F2:8E:19:8E:48:C1:93:B0:38:C6:5D:92:DD:F7:BC:07:7B:0D:B5:9E:BC:9B:25:0A:6D:AC:48:C1:18:03:CA printed in the README, and the release page behind every download, because the project's own disclaimer says the contents, safety and behaviour of those downloads are the responsibility of their authors, not of Komi Store. If you need a curated catalogue with a security review behind each listing, this is the wrong layer.

Frequently asked questions

What is Komi Store?

It is a cross-platform app store for GitHub releases that also covers Codeberg and Forgejo, designed to simplify discovering and installing open-source software. It is written in Kotlin and runs on Android, Windows, macOS and Linux.

Is Komi Store safe?

The README's disclaimer states that Komi Store only helps you discover and download release assets already published on GitHub by third-party developers, and that it does not review, validate or guarantee that any installer is safe, free of malware or fit for any particular purpose. The app publishes an APK signing certificate SHA-256 that you can compare against the certificate your device reports.

How do I install Komi Store?

The README gives Scoop and WinGet commands for Windows, a Homebrew tap and cask for macOS, and points Android users to the GitHub releases page and F-Droid under the package zed.rainxch.githubstore. macOS builds are not notarized yet, so the README tells you to allow the app via System Settings, Privacy & Security, Open Anyway.

Is there a GitHub app store?

Komi Store is one: it browses release assets published on GitHub, Codeberg and Forgejo and installs them from a single client. It was formerly named GitHub Store.

Which open source app store is the best for Android?

The README does not rank app stores, so this cannot be answered from the project's own documentation. What can be said is that Komi Store and F-Droid take opposite approaches: F-Droid builds from source and signs with its own key, while Komi Store installs the binaries developers publish themselves.

Official sources

  1. komi-store/komi-store on GitHub
  2. License: Apache-2.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/komi-store-komi-store.svg)](https://hysenlabs.com/projects/komi-store-komi-store)