-
Notifications
You must be signed in to change notification settings - Fork 27
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
clearly mark debug signing certificates as insecure #1
Comments
How would Reproducible F-Droid Apps based on Debug certs be labeled ? |
Oh my, if that's true then it should be reported immediately to the developers |
Those developers aren't very interested... |
Certainly a discovery I didn't expect to make. While neither of them appears to be public, if the dev wants to continue providing GitHub releases signed (and visible to a user, assuming they look/care for who signed the apk) like this that's fine (maybe?) but those should never make it onto F-Droid reproducible. Especially with Izzy currently pushing to remove (getting them re-signed correctly) all of them from his repo.
As I could obviously write/edit whatever I want
Also probably should've included the "non public (to my knowledge)" part in my first comment. Does the official F-Droid client clearly label Reproducible Builds ? Someone before me had a look and must've approved it. What I am however aware of and did read through (probably something everyone actively using Iceraven should) is fork-maintainers/iceraven-browser#169 |
the title says it all
The text was updated successfully, but these errors were encountered: