19

So I run Linux for a bit now but I am still not fully confident with downloading "random" Appimages or .tar archives (I don't even know how to run/compile the archives but that is another problem lol) from Github or something.

I try to verify the hashes or GPG signatures for all the programs but not every developer provides a latest.yml.

I revently noticed sometimes Github shows a sha256 sum next to the files in the release tab but not in every repo and is this just a second layer or is this a substitution for the latest.yml?

Is there something I am missing or should I not worry too much when using Appimages or Flatpaks because they are sandboxed anyways?

you are viewing a single comment's thread
view the rest of the comments
[-] nykula@piefed.social 9 points 1 month ago

To make binaries trusted, reproducible builds are a thing. People build the same software from source independently and get the same binaries. Then it can be said that the binaries haven't added code missing from the source. It is a difficult goal to achieve because how many complex moving parts are needed to build modern software. Much work relies on distributions' standardized packaging infrastructure. Read more about monthly achievements in this field: https://reproducible-builds.org/

this post was submitted on 20 Apr 2026
19 points (100.0% liked)

linux4noobs

3208 readers
21 users here now

linux4noobs


Noob Friendly, Expert Enabling

Whether you're a seasoned pro or the noobiest of noobs, you've found the right place for Linux support and information. With a dedication to supporting free and open source software, this community aims to ensure Linux fits your needs and works for you. From troubleshooting to tutorials, practical tips, news and more, all aspects of Linux are warmly welcomed. Join a community of like-minded enthusiasts and professionals driving Linux's ongoing evolution.


Seeking Support?

Community Rules

founded 2 years ago
MODERATORS