Damus
Juraj🏴💛🌘 · 1w
Very nice. I'll try to tackle this somehow. A bit more community ideas before. Questions: I would tie this to source code, not APK. Problem is most don't do reproducible builds and we probably audit ...
Zapstore profile picture
Good point, and true there are few reproducible apps.

Would be nice to tag a version (as per Software Applications NIP) against which the latest analysis was run, rather than a git commit.

These reports also contribute to reputation to the keystore/certificate signing the APK so they help anyway.
2❤️1
incoghs102 · 1w
Your doing great work!
Juraj🏴💛🌘 · 1w
Yes, let's do both. Commit is what was audited, version tag is what developer claims the apk is from. BTW it's possible to also audit a binary APK these days, so I wouldn't rule out APK audits, it's just not what most people will do.
Based Truth · 1w
Bill Gates' Microsoft and Google's Alphabet will love this vague "reputation" system, further entrenching their monopoly.
Primal Protocol · 1w
Version tagging is crucial for reproducibility.