How is it possible, that Signal still only provides a .deb package and no .rpm, or even better AppImage or Flatpak? There is an unofficial Flatpak but is it secure?

  • HoornseBakfiets@feddit.nl
    link
    fedilink
    arrow-up
    7
    ·
    edit-2
    3 months ago

    As a maintainer of another unofficial flatpak:

    You can always check the source code of the flatpak (code that downloads the dev then runs it inside the flatpak sandbox) here: https://github.com/flathub/org.signal.Signal

    Any of the current maintainers could add malicious code, but that would ruin their GitHub & by proxy:Twitter,LinkedIn credibility.

    Flathub have final say on what is built and hosted on their flatpak repository (Flathub != Flatpak) and are able to remove versions at will.

    • HoornseBakfiets@feddit.nl
      link
      fedilink
      arrow-up
      3
      ·
      3 months ago

      Personally I don’t understand the large warnings on flatpaks built by others, by that logic you should get a warning sign each time you download from the Ubuntu community apt repository.

      OSS is built out of love, and to me this warns guilty before proven innocent.

      • theorangeninja@lemmy.todayOP
        link
        fedilink
        arrow-up
        2
        ·
        3 months ago

        Well I think you have to distinguish between a messenger and other programms, because a messenger has a lot of sensitive data.

  • TimLovesTech (AuDHD)(he/him)@badatbeing.social
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 months ago

    Could always do what looks like the Arch AUR package is doing and build it yourself from source. Or if you are running a Fedora/OpenSuse distro you could find a package on COPR or something that converts a package from a .deb to .rpm and just change source and stuff to match signal.

  • Rimu@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    I have the official Signal Desktop flatpak installed through Discover. It exists.

  • TimLovesTech (AuDHD)(he/him)@badatbeing.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 months ago

    OP, what distro are you running? You mention a whole bunch of package formats they don’t provide, but never mention what format you require. Depending on the distro, making a build script (or converting the .deb) really isn’t Rocket Surgery ™.

    • theorangeninja@lemmy.todayOP
      link
      fedilink
      arrow-up
      1
      ·
      3 months ago

      Signal aims to be the messenger you can tell your grandma to use. To live up to that promise they have to provide more packages.

      • TimLovesTech (AuDHD)(he/him)@badatbeing.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 months ago

        What percentage of Signal users is “grandma” that uses Linux and would be messaging from her PC? I would have to imagine the overwhelming vast majority of Signal users are on mobile only, so packaging for specific distros is probably far down the priority list.