Comment on Is it safe the new Syncthing-Fork v2.0.14 on F-Droid?

<- View Parent
ilmagico@lemmy.world ⁨1⁩ ⁨day⁩ ago

I don’t use syncthing (anymore) and didn’t know the story behind this, but one thing I know is, f-droid builds the apk from source and signs it with their keys, or if reproducible builds are available, it verifies the signed apk provided by the maintainer to match bit-for-bit with the source code, so at least even if one doesn’t trust the new maintainer, they should be able to trust f-droid that the apk matches the source, so e.g. no spyware or malware was added for example. Sure, someone still needs to review the source, of course.

source
Sort:hotnewtop