What is Nostr?
auggie
npub16ux…lra7
2025-01-02 19:02:18
in reply to nevent1q…kmsn

auggie on Nostr: My bet is it's zap.store signs a bunch stuff themselves. For example, primal on ...

My bet is it's zap.store signs a bunch stuff themselves. For example, primal on zap.store is signed by zap.store and that is probably the zap.store dev doing the link aggregating from github you're talking about, but this kinda defeats the purpose IMO, but olas for example has a pipeline that signs and publishes to zap.store, which is how it's supposed to be used. Otherwise you're basically just substituting your trust of Google to zap.store supported by a web of trust (most of which probably don't know what the fuck they're actually downloading)
Author Public Key
npub16ux4qzg4qjue95vr3q327fzata4n594c9kgh4jmeyn80v8k54nhqg6lra7