> Now, maintainers, who provide the application, suddenly want users to just trust them without being able to easily verify what changed in a release. This is in clear conflict with the "don't trust, verify" approach.
+1 on this, reject black box binaries