Add Hash of App Signing Key to Github README #891
-
Some users may choose to install DAVx5 via the apk downloaded directly from github or using Obtainium instead of fdroid, possibly due to fdroid signing all apps with their own developer signing key, or a route involving an app store. If users choose one of the former two routes, they currently have no way to verify the app was signed by the actual developers because the hash of the signing key isn't posted anywhere (that I've found). Verification is typically done using termux or AppVerfier using its integration with Obtainium. Please consider posting the SHA-256 hash of the developer signing key used for the pre-built apk releases on github. |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 1 reply
-
The hash of the signing key appears to be I could create a PR of the README if the project would find it useful. |
Beta Was this translation helpful? Give feedback.
-
I agree, please publish your public key hash so that we may verify the integrity of your application. Thank you! |
Beta Was this translation helpful? Give feedback.
-
See #919 and https://www.davx5.com/download |
Beta Was this translation helpful? Give feedback.
See #919 and https://www.davx5.com/download