This issue was discovered during an internal audit by Denis Kasak, a security researcher at Element.
A major thank you to Denis Kasak. It's good to know we have talented people like him watching out for the community.
An open network for secure, decentralized communication
This issue was discovered during an internal audit by Denis Kasak, a security researcher at Element.
A major thank you to Denis Kasak. It's good to know we have talented people like him watching out for the community.
F-Droid has been updated now.
Nheko hadn't gotten new releases for quite some time. Perhaps this time...
https://github.com/Nheko-Reborn/nheko/issues/723#issuecomment-918396951
Edit: Old comment is not correct. Updated this comment with correct information
How do you switch to the nightly build on Flatpak?
There is a download flatpak nightly button in the readme file. You can download the flatpak from here https://github.com/Nheko-Reborn/nheko
I get this error when I try to install the Flatpak nightly file
Warning: Can't pull from untrusted non-gpg verified remote
Hello. I dont know too much about this. Can you post this in the nheko matrix room? You will get the response from the developer. https://matrix.to/#/#nheko:nheko.im
I've been advised to use this ref file instead
https://github.com/Nheko-Reborn/nheko/blob/master/nheko-nightly.flatpakref
For more information: https://github.com/Nheko-Reborn/nheko/issues/723#issuecomment-918396951
Please read this post from the developer of Nheko.
I just installed it today from fdroid. Am i safe?
You need to check the actual build date. Fdroid builds tend to be a bit behind, but maybe they specifically made a new build because of the pre-disclosure.
Looks like the f-droid version hasn't been updated yet. I'm on 1.2.0, whereas the fix is 1.2.2. I'm hoping they'll push a release soon.
EDIT: they've pushed an update
I assume yes, usually the F-droid application takes a little bit more to be released, but I'm sure they made some stuff to release it quicker, that was the case with the flatpak package, which tends to do the same. I would still check the latest released version on GitHub just to be sure, though.
They released the updated version recently: https://mastodon.technology/@fdroidorg/106930341765221275