• Pika@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    1
    ·
    edit-2
    12 hours ago

    this entire thing has made me really rethink whether I want to swap to the new repo or not.

    Why was there no communication about it. The gplay repo maintainer wasn’t informed of anything, no public notice to anyone was given, just a transfer of the repo and a status issue here explaining it.

    Obviously the act is genuine as they were able to keep the original keys but like, this entire system seemed really sketchy.

    I’m also not happy with the fact that it seems the first thing they added was removing checksums, but that might be a temp thing.

    I also just noticed that it looks like they removed the entire public key for it, which if they had the original private keys using the existing public keys shouldn’t be an issue right?

    • It’s likely because the app will no longer be distributed on Google. They likely removed the Google play signing keys and configuration, which is completely fine. I’ll have a look over their changes when I get home, but I doubt it’s anything nefarious.

      I also ditched this stuff when Google decided to start asking for my drivers license and will no longer distribute my apps within their closed marketplace.