Comment on PSA syncthing-fork has changed owners
pulsewidth@lemmy.world 2 days agoSounds like a really good reason not to use Obtainium, if any repo you have tracked for updates can just redirect you to a completely different repo - and throw no complaints when updating to an entirely different apk.
With F-Droid they at least have to have the same signing keys, and the code must be a replicable build by F-Droid’s internal apk signature copying process - meaning the code for the supplied APK always matches the code on the repository for the build.
WhyJiffie@sh.itjust.works 2 days ago
that’s not a requirement. or was it already being built reproducibly?
pulsewidth@lemmy.world 2 days ago
Every Catfriend build since v2 has been reproducable. Most apps on F-Droid are and they are encouraging it for all devs, to build trust.
…f-droid.org/…/com.github.catfriend1.syncthingfor…