About this project

AutoMorpheBuilder is a GitHub Actions pipeline that builds patched Android APKs using Morphe patches, morphe-desktop and APKEditor. Outputs are signed, versioned per app, and formatted so Obtainium can track updates. Forking for personal use is encouraged; adding or removing an app only requires editing patch_repos in config.json, with no workflow changes. The README lists tested apps including YouTube, YouTube Music, Reddit, Sofascore, Twitch, NZB360, AIDA64, Mimo and Flightradar24, each mapped to a package name and an upstream patch repository. A legal and security notice states that the project downloads and modifies third-party applications from sources such as APKMirror and APKPure, that users are responsible for complying with each app's license and local law, and that no copyrighted APK is hosted or redistributed because every APK is fetched at build time from the configured upstream source. Builds are signed with the user's own keystore, and those secrets are treated as production credentials. Four workflows are documented. morphe-build.yml runs daily at 05:15 UTC and manually; check-versions resolves latest tags and skips apps whose release already exists, a per-app matrix build downloads the APK, applies patches and signs it, and create-release publishes one GitHub Release per app while pruning the oldest and keeping two per app. update-patches.yml refreshes patches.json from upstream patch repositories, defaults new patches to enabled and preserves existing toggles. ci.yml runs npm ci, eslint and jest on pull requests and pushes to main. codeql.yml performs static security analysis for JavaScript/TypeScript and Actions. Release tags follow the pattern app-vbase-version-patches-version, for example youtube-v20.44.38-v1.24.0-dev.8.apk. The README explains creating one Obtainium entry per app against the repository with a Release Tag Filter matching the app name, and provides ready-made Obtainium links for the tested apps. Required secrets include KEYSTORE_BASE64 and KEYSTORE_PASSWORD, which are mandatory because signed builds are enforced; KEY_ALIAS and KEY_PASSWORD are optional, and APKMIRROR_API_USER and APKMIRROR_API_PASS optionally skip the Playwright fallback. APK download uses a multi-source fallback: pre-downloaded tools APKs, a URL cache, configured download_urls, then parallel resolution through apkeep for APKPure, APKMirror-API when credentials are set, and an APKMirror scraper with a Chromium fallback. Split packages such as XAPK, APKM and APKS are saved as .apk and detected by content rather than extension, with the inner base.apk validated after merging. APK selection prefers an architecture from config.json, defaults to arm64-v8a, applies DPI preferences for APKMirror, merges split packages with APKEditor or falls back to dex-bearing APK extraction, and rejects APKs without classes dex files. Signing decodes the keystore, passes it to morphe-desktop patch with password, entry password and entry alias options, lets morphe-desktop detect PKCS12, JKS or BKS and convert internally, signs the patched APK in place, and fails immediately on any signing error without an unsigned fallback. The README documents common failures with causes and fixes, including missing classes dex, undetermined versions, wrong keystore passwords, mislabeled architecture bundles and Obtainium not finding updates. Further documentation covers configuration fields, pipeline architecture and the check-versions to build to create-release job graph, a troubleshooting catalogue, the release process and rollback, setup steps for forking and configuring secrets, contribution guidance and a security disclosure policy. The project is licensed under GPL-3.0.