kylejbrk / standard-notes-open-extended

A Free Open Source Standard Notes Extensions Repository Hosted via Github Pages
https://kylejbrk.github.io/standard-notes-open-extended/
GNU General Public License v3.0
111 stars 58 forks source link

Sorry if dumb question - how do I verify security? #12

Closed Penguinjumper closed 2 years ago

Penguinjumper commented 2 years ago

So as far as I'm getting it (not in IT or something) - this makes my standardnotes-clients get the original editors in the end, right? Now I love this, but the idea of SN is very private, encrypted note-taking. Could the privacy of my notes become compromised, if, say, one of you guys working on this project changed something in the code, making my program fetch a corrupted update for an extension, which would share my note contents with a malicious actor?

Just want to be sure I understand how this works and how safe it is. Thanks a lot for your work! :)

kylejbrk commented 2 years ago

Theoretically sure.

But the way this project works is that it pulls standard notes extensions from the official repos only. You can verify this yourself by checking the code and the extensions folder. Also if you dont trust me to host your extensions (im just hosting them here on github pages), you have the option of forking the repo so you host it yourself.

Also please be aware of https://github.com/kylejbrk/standard-notes-open-extended/issues/10. The project is not as convenient to use as it once was, but you can still import the individual extensions.