Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Warrant Canary #52

Open
PF4Public opened this issue Oct 19, 2020 · 0 comments
Open

Warrant Canary #52

PF4Public opened this issue Oct 19, 2020 · 0 comments

Comments

@PF4Public
Copy link
Owner

PF4Public commented Oct 19, 2020

This overlay has a number of ebuilds for Gentoo, which are publicly available to anyone. Their integrity is guaranteed by Git VCS.

  • I'm not aware of any modification of the content of this overlay by any third party: neither ongoing, nor in the past
  • I haven't received any information on any modification of the content of this overlay by any third party: neither ongoing, nor in the past

Apart from ordinary ebuilds this overlay provides binary releases of ungoogled-chromium. Their integrity is guaranteed by checksumming after uploading and downloading from GitHub.

  • I certify that binary releases of ungoogled-chromium are compiled from the very ebuilds in this overlay and from the same sources
  • I certify that binary releases of ungoogled-chromium are compiled on systems, to which I have complete access and which are under my full control
  • I'm not aware of any modification of the content of binary releases of ungoogled-chromium of this overlay by any third party: neither ongoing, nor in the past
  • I haven't received any information on any modification of binary releases of ungoogled-chromium of this overlay by any third party: neither ongoing, nor in the past

Please let me know if you discover any occasion of modification of either content of this overlay or binary releases of this overlay by any third-party.

Possible weak point is that currently checksumming is happening after a binary release is uploaded to GitHub and downloaded. I doubt GitHub be doing shady things in-between, but if this situation troubles you, please inform me (best if you also have a solution to this issue).

Some related ranting I've just read about an extension, maintainer of which did sell (or whatever he did to lose control over) it, which had a number of (many?) contributors and users, and most importantly, which was concerning privacy, but the most troubling in my opinion is the complete lack of a prior notice, transparency or something alike for end-users. That was a terrible course of events, to say least.
Repository owner locked and limited conversation to collaborators Jan 17, 2022
Repository owner unlocked this conversation Feb 16, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant