• Pika@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    1 hour ago

    this entire thing has made me really rethink whether I want to swap to the new repo or not.

    Why was there no communication about it. The gplay repo maintainer wasn’t informed of anything, no public notice to anyone was given, just a transfer of the repo and a status issue here explaining it.

    Obviously the act is genuine as they were able to keep the original keys but like, this entire system seemed really sketchy.

    I’m also not happy with the fact that it seems the first thing they added was removing checksums, but that might be a temp thing.

    I also just noticed that it looks like they removed the entire public key for it, which if they had the original private keys using the existing public keys shouldn’t be an issue right?