• FizzyOrange@programming.dev
    link
    fedilink
    arrow-up
    8
    ·
    5 days ago

    that they would disclose on their website

    Wouldn’t it make more sense then for them to simply host the Flatpak themselves? I kind of thought that was the whole idea of Flatpak.

    • Kazumara@discuss.tchncs.de
      link
      fedilink
      arrow-up
      7
      ·
      5 days ago

      Best to do both, really, so a record of using a consistent public key is created.

      Then supply chain attacks might be noticed. If someone manages to replace the file on the webserver but can’t get to the signing key you’ve prevented the attack.