• AmbiguousProps@lemmy.today
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    5 months ago

    The new repo has two releases in it now. These releases are not signed with the original key as far as I can tell. Further, GitHub is silently redirecting to the new repo, even in Obtainium, meaning it’s possible that if you had this previously installed via Obtainium and updated now, you may have unsigned apks installed that may or may not contain the changes in the repo.

    This is a mess. I deleted the repo from Obtainium (luckily I don’t auto install updates) and will wait to see what happens over the next few months. Might just save my notes in a network share instead of using syncthing from my phone. Idk, notes are all that I was using it for.

  • Wispy2891@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    5 months ago

    Maybe it’s actually true that catfriend1 knows the new owner in real life but… this is not a calculator app, this is something that has complete access to the phone storage… handing the keys without any communication is concerning…

    And the issues are locked so if something nefarious happens, discussion will only occur somewhere else instead of the repo

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      And the issues are locked so if something nefarious happens, discussion will only occur somewhere else instead of the repo

      people shouldn’t count on that anyways because the repo owner can delete issues, comments, also edit them