zlacker

[return to "F-Droid Fake Signer PoC"]
1. kuschk+X8[view] [source] 2025-01-04 00:07:27
>>pabs3+(OP)
While none of that applies to F-Droids primary use case (the primary F-Droid repo builds all apps from source itself), it nonetheless looks like they failed to correctly handle the issue.

The only reason this didn't turn into a disaster was pure luck.

◧◩
2. wkat42+xb[view] [source] 2025-01-04 00:33:09
>>kuschk+X8
Yeah that's the big benefit of F-Droid, reproducible builds. It builds directly from github. I like that aspect of it a lot, it adds a lot of security that other app stores don't have.

But yeah other repos don't :(

[go to top]