View Issue Details

IDProjectCategoryView StatusLast Update
0000195NoteFlybugpublic2016-07-24 00:44
ReporterD9ping Assigned To 
PrioritynormalSeverityminorReproducibilityhave not tried
Status resolvedResolutionfixed 
Summary0000195: Migrate way from sourceforge
DescriptionSourceforge is bundling software with adware stub installers.

source:
http://www.ghacks.net/2013/07/17/sourceforges-new-installer-bundles-program-downloads-with-adware/

Because the NoteFly updater does integity checking with RSA this stubinstaller is regarded as unauthentic modified file.

And updating NoteFly will fail then.

Steps To ReproduceSeek a alernative way to distrubed the setup files worldwide.
Additional InformationPossible other ways to distrubed NoteFly with good download speeds worldwide.

- Cloud storage provider public folder.

- Bittorrent
TagsNo tags attached.

Activities

D9ping

2013-12-08 16:27

administrator   ~0000174

It's opt-in so NoteFly has yet no problems from this.
source: http://sourceforge.net/blog/today-we-offer-devshare-beta-a-sustainable-way-to-fund-open-source-software/

D9ping

2014-07-14 22:47

administrator   ~0000176

Marking this issue as resolved as sourceforge has clarified it was optional. Reopen if it happens again or turns out not to be optional.

D9ping

2015-06-02 15:26

administrator   ~0000183

Last edited: 2015-06-03 15:46

Issue re-opend(new status: feedback) because of again a case in which sourceforge is using adware.<sup>1</sup> <sup>3</sup>

Sourceforge offers worldwide lots of mirrors and thus good download speed worldwide for opensource projects. But they promise not to bundle their adware installer with our software<sup>2</sup>.

I said this in plain English: I don't want NoteFly to come with bundled software.

The question is: can we trust sourceforge not to bundle NoteFly with adware?




sources:

1 https://mail.gnome.org/archives/gimp-developer-list/2015-May/msg00098.html

2 http://sourceforge.net/blog/third-party-offers-will-be-presented-with-opt-in-projects-only/

3 http://arstechnica.com/information-technology/2015/06/sourceforge-locked-in-projects-of-fleeing-users-cashed-in-on-malvertising/

D9ping

2015-06-03 15:32

administrator   ~0000184

Last edited: 2015-06-04 20:11

Now sourceforge again bundling adware with Nmap.<sup>1</sup>

NoteFly decided to stop using the download link to sourceforge on the download page for now.

NoteFly now also mirrors it's sourcecode repository on github.

The sourcecode is now also on: <code>https://github.com/NoteFly/NoteFly</code>



sources:

1 http://seclists.org/nmap-dev/2015/q2/194
2