TeamNewPipe / NewPipe

A libre lightweight streaming front-end for Android.
https://newpipe.net
GNU General Public License v3.0
31.09k stars 3.02k forks source link

publish hashes of signing keys #11430

Open grrrrr opened 1 month ago

grrrrr commented 1 month ago

Checklist

Feature description

On Android, you can use AppVerifier to confirm if an apk was signed by the owners or an untrusted key (as well as other methods). This can be combined with Obtanium to check at install time.

The hashes could be published in a number of places for additional trust. e.g

Why do you want this feature?

Allows for an additional layer of certainty being able to easily check that the apk is legitimately signed

Additional information

tangentially related to #5469

bats6931 commented 3 days ago

FWIW these are currently published in the homepage, under the "Get NewPipe" section: https://newpipe.net. Got my green AppVerifier checkmark :)