Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Add unofficial Debian package repository #4398

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

dariogriffo
Copy link

  • PR Description

  • Please check if the PR fulfills these requirements

  • Docs have been updated if necessary
  • You've read through your own file changes for silly mistakes etc

@ChrisMcD1
Copy link
Contributor

I'm not familiar with the world of unofficial debian repositories. And with that lack of familiarity, linking to this feels naively feels like it could introduce a malicious version of lazygit into someone's machine if your system is compromised.

Is there some reason this wouldn't introduce a new vulnerability into the chain of trust?

@dariogriffo
Copy link
Author

dariogriffo commented Mar 16, 2025

Is there some reason this wouldn't introduce a new vulnerability into the chain of trust?

I cannot account for other repos. My build process is public so you can see how the packages are created. Everything is automated and published first to GitHub as artifacts so people can even download those.
But you can verify the integrity simply checking md5 sums.
I host tools that I use on daily basis and have no Debian package.
I'm planning to add I'm the short term Claude desktop, and yazi a terminal file manager, but things take time :)

At the end is a matter of trust, people uses lazygit and they don't know if it is doing something on the background with your data.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants