• Great Blue Heron@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 minutes ago

    I installed mine from F-Droid. I just went there to turn off updates and it doesn’t exist. I have not been paying attention so it may have been gone for ages and not related?

  • spacelord@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    9
    ·
    1 hour ago

    I wouldn’t say it’s only for the extra paranoid, but rather for everyone.

    After reading the whole discussion, it’s clear that the repo transfer was handled in an extremely unorthodox way, at least by usual standards for repo handovers that I’m familiar/experienced with.

    Communication from Catfriend1 was absolutely nonexistent, and there was only minimal info from the person who took over using a GitHub account created just two days ago.

    Trust is something that must be earned, not given to someone you’ve never seen or heard of before.

  • ultranaut@lemmy.world
    link
    fedilink
    English
    arrow-up
    20
    ·
    4 hours ago

    Not sure if I qualify as extra paranoid but this whole situation feels very sketchy and has me reconsidering my use of syncthing. Making significant changes like this without any explanation is extremely bad practice.

    • unexposedhazard@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      28
      ·
      edit-2
      4 hours ago

      has me reconsidering my use of syncthing

      This is about a third party piece of software that isnt directly related to syncthing. The devs of syncthing have however been recommending syncthing-fork as their choice for android, so it definitely needs clearing up.

  • BackgrndNoize@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    3 hours ago

    My policy with open source projects like these is to fork the repo and only bring in upstream updates when I’m certain it’s safe and necessary

    • Serinus@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      32 minutes ago

      Which is just as risky as instantly updating unless you’re really closely keeping an eye on which updates are security related.

    • kokomo@lemmy.kokomo.cloud
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      2 hours ago

      that’s probably what I might do and build apks myself with forgejo. and/or pull in nel0x’s fork instead and build from his code.