4 ms·
What pcmonk said. And: * I'm a dschep, sorry I don't work at keybase * it's open source * extensions are easy to unpack & view the source if you don't trust
by dschep 8y ago
What pcmonk said. And:
* I'm a dschep, sorry I don't work at keybase
* it's open source
* extensions are easy to unpack & view the source if you don't trust I'm not tampering the extension before upload
* I do no obfuscation of the JS, it's only 201 LOC
- giancarlostoro 8y ago> * extensions are easy to unpack & view the source if you don't trust I'm not tampering the extension before upload Surprised browsers plugin centers (stores?) don't let you just put your github repository and build your extension depending on a given branch (or tags) and then informs the user that the extension was directly pulled from GitHub or other version control sources (and provides a direct link) it would be a little more interesting.
- vivan 8y agoThat would mean they get published without any checks - an easy attack vector for malware.
- giancarlostoro 8y agoIf pull requests are auto accepted sure? But that shouldn't normally be the case.
- dschep 8y agoThat'd be neat. Like docker hub supports and f-droid requires(IIRC)!