unSATiated's avatar
unSATiated 4 months ago
That's true, but it's also possible for an attacker to compromise a GH account and publish a new "release", without even changing any source code. Only you have all the accounts to secure, and only one F-Droid. I use Obtainium too, but it's unclear to me how to weigh up these risks.

Replies (1)

Tim's avatar
Tim 4 months ago
Very true, got to stay vigilant than I guess.