Do you write #Python programs that use #Git? Would you like a dead simple method for fetching public untrusted git repos in the most secure method possible? That's what we've put together in this pull request:
https://github.com/gitpython-developers/GitPython/pull/2029
If that is interesting to you, please try it out, give feedback, give it a thumbs up, etc.
@ret @fdroidorg We have never even tried to please everyone because it is clearly impossible. Thinking about the user helps deal with the world as it is. Let's take your example to show how difficult and gray this is: clearly the LGBTQ users in Saudi want privacy. If Saudi bans F-Droid and arrests users because of that app, did we best serve your example user? If F-Droid has a neutral reputation, provides strong privacy and decentralized access to apps, would your example user be better served?
What time it is? It's 5 o'clock... somewhere. So here comes the fifth #FDroid legal post.
It's all about content, transparency, and user protections. It features strong tags like #OnlineSafetyAct #Ofcom #DSA and #DMA and how these shape our own policies.
Will this break some prejudice? One way to find out: https://f-droid.org/2025/10/21/navigating-the-digital-markets-act-digital-services-act-and-the-online-safety-act.html
@muntashir @Epic_Null @emaksovalec @IzzyOnDroid You're right, F-Droid does really need to think about the definition of users we use and stick to it. It turns out, we have been doing a lot of that since the beginning. We do it in public and welcome all constructive engagement. For example, on the topic of app inclusion:
For discussions, check the currently active https://forum.f-droid.org or https://gitlab.com/fdroid or even archive, like from 2012 https://f-droid.org/forums/post/1301/index.html
@Epic_Null @muntashir @emaksovalec wow you really nailed it! Thanks for this, it gave me quite a needed boost to continue working on F-Droid.
@nobody The FSF is a fiscal sponsor of the Guix project, together with Guix Foundation, but the FSF does not contribute per se to Guix development (even less so now that the project no longer uses FSF infra).
@cryptax 🤣 😭 here's an insane visual to your post:
@cryptax yeah, I have that feeling too, and I'm a Debian Developer even. Its a tricky balance. Debian takes a free-software-first stance and tries to push all work upstream as much as possible. That means in the short term, many devices are less polished. Ubuntu and Mint put a lot of effort to polish their own releases by including customizations and quirks in their forks. That means they have more polish, but means wasted effort in the long term. It is a tricky thing to balance.
@nobody @signalapp GNU is still central to GNU/Linux and GNU/Linux is central to building Android, GrapheneOS, Debian, Tails, Qubes, etc. Even macOS ships GNU. Maintenance counts. Don't forget maintenance.
Then like you said GNU Guix is leading the charge on strictly bootstrapable systems. And GNU Taler is leading the charge on privacy-respecting digital currencies, like real ones that aren't based on scams.
🔞 Platforms have no excuse to continue practices that put children at risk.
We’ve asked Snapchat, YouTube, Apple App Store and Google Play for more information on the measures they have in place to protect minors.
This is the first investigatory step after the adoption of the Guidelines on the Protection of Minors, now also available in all EU languages and in a child- and parent-friendly version.
@nobody @signalapp
They said "GNU and FSF promote a bunch of highly insecure operating systems and products which causes real harm to users"
Without GNU and FSF's decades long fight for real free software, we'd be stuck with Microsoft and Apple for our "secure" options. GNU made Linux possible, made Android possible, made Qubes and Tails possible, etc. If you care about getting to real security, where everything is free software that can be inspected, then supporting efforts like FSF is key
@nobody @signalapp It happened because GrapheneOS claims to do everything for security, but then, dismisses projects that aim to replace binary blobs with free software. So perhaps they did not literally say what I wrote, but that's my synopsis of their logic, as far as I can follow it. I know of no standard to audit binary blobs with any reliability. Moxie was also never a believer in free software, his hand was forced by OTF to make Signal free. It was a requirement to receive funding.
Wow the #enshittification cycle in #AI companies like #OpenAI and #Meta is going fast. Now they're going into dependence-inducing adult content and "sensual" chatbots for kids. How low will they go?
https://x.com/AskPerplexity/status/1978492956869828613
It seems y'all are really missing the point of the FSF in general and its librephone project. They are working to replace binary blobs with free software. I recommend reading their project description:
Why on earth are big #copyright companies so shitty? #Sony #MPAA etc etc. They think they are totally justified to just hit internet service providers with mostly wrong #AIslop infringement notices and have those ISPs do mass service cancellations. All because they need to defend their outdated broken business model that is hostile to digital media and the internet
#Cox is also a pretty bad company, but I'm very happy to support them as they are fighting this in court
@moshimotsu there is a very good reason why security audits are done on source code. Yes, observing behavior is important. Then when one has the source code, one can follow up and confirm the exact behavior. With a binary blob, that is not feasible.