trezor / trezor-suite

Trezor Suite Monorepo
https://trezor.io/trezor-suite
Other
723 stars 251 forks source link

Moderation required on SatoshiLabs in the Microsoft winget package repository #4822

Closed brianddk closed 2 years ago

brianddk commented 2 years ago

SatoshiLabs is showing up in the winget package repo. It's great to see the packages there, but you might want to take over the PR submission for your ORG. The packages there seem legit, but technically, anyone could contribute any package there and call it "TrezorSuite". Your dev team may want to take over these submissions, or request you appear on the PR approval list for your ORG.

tsusanka commented 2 years ago

Hi @brianddk, as there are many package managers out in the wild, it is quite hard to maintain all of them.

As I am looking into the winget repo it seems to me that the Suite apps are taken from GitHub release directly, so that's great and does not have to be changed. Approving the PRs from our side would be nice though.

request you appear on the PR approval list for your ORG.

If you are familiar with the topic, could you please point to some docs how we can do that?

brianddk commented 2 years ago

If you are familiar with the topic, could you please point to some docs how we can do that?

There are proposals in the works, and I've added to the proposal process. SL input would be great as well. It's a fairly heated topic and not yet solidified.

https://github.com/microsoft/winget-pkgs/discussions/15607#discussioncomment-2069357

tsusanka commented 2 years ago

Great! I will try look to into that. As there is not much we can do directly here in trezor-suite, I am closing this one. Thanks for the heads-up and I'll try to look into the discussion at some occasion.

vedantmgoyal9 commented 2 years ago

Hi @tsusanka, you can use https://github.com/marketplace/actions/winget-releaser to officially publish trezor-suite to winget repo. A personal access token will be required to create a PR at microsoft/winget-pkgs repo, and microsoft/winget-pkgs needs to be forked under the org/a bot account like @trezor-ci.