I had no idea this issue had been identified. While I find this tool very useful, the project is seeming rather questionable to me now.

  • Even then, he’s still allowed to provide binary blobs. He doesn’t have to provide it as source code. If that was the case, we’d all have to build from source and package managers like apt, dnf and flatpak wouldn’t exist.

    All he has to do is make the source code available, i.e. just link back to the original Github Repo.