GrapheneOS security complaints about F-Droid are a load of nonsense except for one: the APK on the website is signed by a different key from the one that F-Droid updates itself with.
> the APK on the website is signed by a different key from the one that F-Droid updates itself with
Could you explain? I don't understand what you mean here. <a href="https://f-droid.org/F-Droid.apk" rel="nofollow">https://f-droid.org/F-Droid.apk is signed by the same key that signs <a href="https://f-droid.org/repo/entry.jar" rel="nofollow">https://f-droid.org/repo/entry.jar
mightysashiman · · focus · HN ↗
someonebaggy · · focus · HN ↗
eighthave · · focus · HN ↗
Could you explain? I don't understand what you mean here. <a href="https://f-droid.org/F-Droid.apk" rel="nofollow">https://f-droid.org/F-Droid.apk is signed by the same key that signs <a href="https://f-droid.org/repo/entry.jar" rel="nofollow">https://f-droid.org/repo/entry.jar