Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,8 @@ echo "deb [signed-by=/etc/apt/keyrings/guysinc-apt.gpg] https://apt.guysinc.pub/
sudo apt update && sudo apt install github-desktop
```

The same steps with checksums for direct downloads, plus `.rpm` and AppImage instructions, are on the install guide at [guysinc.pub/install.html](https://guysinc.pub/install.html).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checksum claim references an external page that cannot be verified from repo contents

The new sentence promises 'checksums for direct downloads' at guysinc.pub/install.html. The only guysinc.pub HTML file in the repo (apt/index.html) contains no checksums at all. The linked page is external and untracked, so there is no way to confirm the claim is accurate — if the install guide does not actually list checksums, the README misleads security-conscious users who rely on that verification step.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

External link duplicates .rpm and AppImage instructions already present inline in the README

The sentence points readers to guysinc.pub/install.html for '.rpm and AppImage instructions', but those instructions are already written out in full at README.md lines 90–104. This creates two authoritative sources for the same content. When package names, flags, or steps change, the inline README section and the external page can independently drift, leaving one set of instructions stale with no diff to catch it.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Bare URL used as Markdown anchor text, inconsistent with every other link in the file

The new link is [guysinc.pub/install.html](https://guysinc.pub/install.html) — a bare domain as the display text. Every other Markdown link in README.md uses descriptive anchor text: [Releases](...), [Known issues](...), [GitHub Desktop](...), etc. Bare URLs inside code blocks (the apt shell commands on lines 55–57) are command arguments, not anchors, so they do not establish this pattern. The new link is the sole inconsistency.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"The same steps" contradicts "direct downloads" — the apt block sets up a repository, not a direct download

The new sentence says "The same steps with checksums for direct downloads…" but the four lines above (lines 53–58) configure a signed apt repository — they are not direct-download steps. A direct download would mean fetching a .deb file from the Releases page and verifying its checksum; the apt commands do neither. A reader following the install guide expecting "the same steps" as above would be confused. The sentence needs to separate the two ideas: the guide covers (a) direct .deb download with checksum verification and (b) .rpm/AppImage instructions — neither of which is "the same steps" as the apt repository setup.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Link display text is a bare URL, inconsistent with every other hyperlink in the file

guysinc.pub/install.html uses the raw domain path as display text. Every other link in README.md uses descriptive anchor text: "Releases", "Arch Wiki", "roadmap", "Known issues", "README". A consistent fix is install guide, which also makes the sentence read more naturally and removes the redundancy of showing the URL twice.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: AppImage written without leading dot, inconsistent with .AppImage used throughout the file

Line 60 writes AppImage (bare word, no dot, no backticks). The rest of the file uses .AppImage with the leading dot consistently: in the format list (line 45), in the "Other distributions" intro (line 88), and in the install command (line 102). The fix is to write .AppImage to match the style of .rpm in the same sentence.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Link uses bare domain; all other repo URLs use apt. subdomain

The added link points to https://guysinc.pub/install.html, but every other guysinc.pub URL in the repository uses https://apt.guysinc.pub/… (e.g. lines 55–56 use apt.guysinc.pub/guysinc-apt.gpg and apt.guysinc.pub/github-desktop). No other file in the repo references the bare guysinc.pub domain. The intended URL is almost certainly https://apt.guysinc.pub/install.html; as written the link likely 404s.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sentence implies RPM/AppImage instructions exist only externally; they are already in this file

The sentence says .rpm and AppImage instructions are on the install guide at an external link, which implies a reader must leave the README to find those instructions. The README already contains inline RPM install commands (around lines 90–97) and AppImage instructions (around lines 99–104) under the Other distributions section. A reader following the external link pointer will either miss the in-repo instructions entirely or later distrust the README's completeness. The sentence should either remove the RPM/AppImage mention or clarify that the README also covers them.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Sentence interrupts the logical flow between the APT code block and its GPG trust explanation

Lines 55–58 show the APT repository setup commands; lines 62–68 explain why the repository is safe to trust (GPG fingerprint). The new sentence at line 60 redirects readers to an external page, creating a detour between the commands and their security context. A reader who follows the external link and returns may lose the thread and skip GPG verification. Moving the sentence to after line 63, or to the Other distributions section, would preserve the security-explanation flow.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: New sentence interrupts the apt-specific GPG key paragraph

The GPG fingerprint paragraph immediately below ("The repository is GPG-signed...") is contextually tied to the apt repository setup. Inserting the install-guide reference between the code block and the GPG paragraph breaks that logical flow. Moving the new sentence to after line 68 (the end of the GPG key section) would preserve the apt-setup→GPG-key sequence and group the install-guide cross-reference more naturally.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Install-guide reference duplicates RPM/AppImage instructions already in README

The new sentence says RPM and AppImage instructions are on the external install guide, but lines 84–103 already contain those instructions inline. If the two sources ever diverge, readers will not know which is authoritative. Consider phrasing that acknowledges the inline instructions exist: e.g., "...plus RPM and AppImage instructions (also covered below)..." or removing the RPM/AppImage callout from the new sentence.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: "The same steps" lacks a clear referent for out-of-context readers

A reader who arrives at this paragraph via a search hit or deep link has no immediate referent for "The same steps." Rephrasing to "The apt steps above, along with checksums for direct downloads..." makes the sentence self-contained and avoids the ambiguity.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"The same steps" conflates APT-repository setup with direct-download installation

The sentence reads: "The same steps with checksums for direct downloads, plus .rpm and AppImage instructions, are on the install guide." The preceding code block shows 4 commands for setting up an APT repository (curl key, echo sources.list entry, apt update, apt install). "Direct downloads" — downloading a .deb from GitHub Releases and running dpkg — are a completely different installation method. Calling them "the same steps" is inaccurate: a user following this sentence to the external guide expecting a checksum-augmented version of the curl/echo/apt flow will instead find different dpkg commands (or vice versa), creating confusion about which method to follow.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Sentence implies RPM and AppImage instructions only exist on the external guide, contradicting the README's own "Other distributions" section

"plus .rpm and AppImage instructions, are on the install guide" uses "are on" in a way that implies the external site is the authoritative location for those instructions. However, README.md already contains complete, self-contained RPM (sudo dnf install, sudo zypper install) and AppImage (chmod +x, run) commands at lines 90–104. A Fedora or AppImage user reading line 60 has no signal that the README itself covers their case 25 lines later, and is likely to navigate to the external guide unnecessarily — or fail if that guide is unavailable.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

New sentence creates a second source of truth for RPM/AppImage instructions already in the README

The new sentence tells users that .rpm and AppImage instructions are on the external install guide, but README.md already contains full inline RPM and AppImage installation steps in the "Other distributions" section (lines 84–111). There are now two places documenting how to install for those platforms. If the external guide diverges (e.g., adds a dnf copr repository step), a maintainer who updates only one source leaves users with contradictory instructions. Either the inline sections should be removed and deferred entirely to the external guide, or the sentence should be scoped to what the guide adds that the README doesn't cover (e.g., checksums).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sentence interrupts the APT setup flow, increasing the chance users miss GPG fingerprint verification

The added sentence is inserted between the APT install code block (line 58) and the GPG fingerprint verification paragraph (line 62: "The repository is GPG-signed; the fingerprint to verify is…"). The natural reading sequence is: add key → add source → install → verify the signing fingerprint. The inserted sentence pivots to an external link mid-sequence. A user who clicks the link (or stops reading after the code block) may skip the fingerprint verification step, which is a security-relevant action. The sentence would be safer placed after the fingerprint paragraph, or in the "Other distributions" section.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: "The same steps with checksums for direct downloads" is misleading in an APT context

The sentence reads as if the install guide shows a checksum-verified version of the APT steps that precede it. APT installations are GPG-verified by the package manager and do not involve manual checksum verification — checksums are relevant only to direct .deb/.rpm/AppImage downloads. A reader who parses "same steps with checksums" literally may search for a checksum they are expected to verify as part of the APT flow. Rewording to something like "Instructions for direct downloads with checksums, plus .rpm and AppImage instructions" avoids the confusion.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: Cross-distro content (.rpm, AppImage) injected under the Debian/Ubuntu section heading

The sentence mentions .rpm and AppImage instructions while sitting inside the "## Install on Debian / Ubuntu (recommended)" section, which runs until line 84. A Fedora or AppImage user who sees that heading and skips the section will miss the external link entirely. Moving the sentence to the "## Other distributions" section (or adding a brief pointer there) would put it where non-Debian users are most likely to look.


The repository is GPG-signed; the fingerprint to verify is
`F45B B6D3 4D82 EF56 BB97 FBE0 F305 FB33 592B 46C8`.

Expand Down
Loading