Overview here https://forum.syncthing.net/t/does-anyone-know-why-syncthing-fork-is-no-longer-available-on-github/25661/39

The new owner of the repo has a fresh github account and apparently has the signing keys from Catfriend1 too.

Time will tell if they are trustworthy, but for the extra paranoid it might make sense to pause updates for a while.

The new repo has two releases in it now. These releases are not signed with the original key as far as I can tell. Further, GitHub is silently redirecting to the new repo, even in Obtainium, meaning it’s possible that if you had this previously installed via Obtainium and updated now, you may have unsigned apks installed that may or may not contain the changes in the repo.

This is a mess. I deleted the repo from Obtainium (luckily I don’t auto install updates) and will wait to see what happens over the next few months. Might just save my notes in a network share instead of using syncthing from my phone. Idk, notes are all that I was using it for.

OC text by @AmbiguousProps@lemmy.today

  • teolan@lemmy.world
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    3 hours ago

    Thanks for the heads up!

    Thankfully I installed it through F-Droid, so I’m prettyvsafe withe regards to weird updates being pushed without knowing what’s happening. Syncthing is so useful it’s a shame it’s not good on Android.