[GH-ISSUE #80] Move away from SourceForge #46

Closed
opened 2026-05-05 04:53:42 -06:00 by gitea-mirror · 1 comment
Owner

Originally created by @pyther on GitHub (Oct 11, 2015).
Original GitHub issue: https://github.com/netblue30/firejail/issues/80

In the recent past, SourceForge has gained a really bad reputation (non-https downloads, adware-sprinkled installers). See this and this.

Due to these events, I can not trust any code and/or binaries served from sourceforge. I almost passed up a great piece of software because this github project did not show up in my search results for "firejail" and the firejail website links to sourceforge.

Action Items

Originally created by @pyther on GitHub (Oct 11, 2015). Original GitHub issue: https://github.com/netblue30/firejail/issues/80 In the recent past, SourceForge has gained a really bad reputation (non-https downloads, adware-sprinkled installers). See [this](http://www.howtogeek.com/218764/warning-don%E2%80%99t-download-software-from-sourceforge-if-you-can-help-it/) and [this](http://arstechnica.com/information-technology/2015/05/sourceforge-grabs-gimp-for-windows-account-wraps-installer-in-bundle-pushing-adware/). Due to these events, I can not trust any code and/or binaries served from sourceforge. I almost passed up a great piece of software because this github project did not show up in my search results for "firejail" and the firejail website links to sourceforge. Action Items - update links in source code. PR #79 - serve packages and binaries from github. [about-releases](https://help.github.com/articles/about-releases/) - update links on the firejail website (https://l3net.wordpress.com/projects/firejail)
Author
Owner

@netblue30 commented on GitHub (Oct 11, 2015):

I know about the problems with SourceForge. Unfortunately for now the downloads will stay on SourceForge mirror system. Everything else on SourceForge is being phased out.

For each release I add a firejail-X.Y.Z.asc file with sha256 checksums for all downloads in the release. The .asc file is signed with GPG and can be checked by the user.

<!-- gh-comment-id:147187736 --> @netblue30 commented on GitHub (Oct 11, 2015): I know about the problems with SourceForge. Unfortunately for now the downloads will stay on SourceForge mirror system. Everything else on SourceForge is being phased out. For each release I add a firejail-X.Y.Z.asc file with sha256 checksums for all downloads in the release. The .asc file is signed with GPG and can be checked by the user.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/firejail#46
No description provided.