delirious_owl,
@delirious_owl@discuss.online avatar

No, my point is that if flat pak doesn’t document that they cryptographically verify the authenticity of packages, then they dont.

Even the ostree docs say that it supports it gpg encryption. It supports it. It doesn’t enforce it. That depends on the implementation.

I will continue to harshly criticize projects that leave users vulnerable. Want to prove me wrong? Link me to the flat pak docks that clearly say that all packages are cryptographically verified after download and before upload.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • linux@lemmy.ml
  • fightinggames
  • All magazines