Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The whole idea of me reviewing software before I install it breaks when I can’t easily install it from the source I reviewed.

This reminds me of why GitHub should create it’s own App Store (yup, I’m gonna beat this drum):

I can navigate the source ask questions about parts that make me suspicious, and then install a prebuilt binary with confidence that the binary was the sum of what I reviewed.



To be explicit: This depends on the app store only allowing CI builds, since otherwise you can't trust that the binaries match the source.


Or allowing local builds with including custom patches. Giving people agency over the machines that run their lives is way too radical to be popular though.


This is the approach of fdroid which is what imo makes it trustworthy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: