During the bootstrap phase only this nsec is signing releases but I'm building tools for developers to sign their own. Since there is no centralized source of truth anyone can claim an app is theirs, hence the importance of the social graph to establish trust and weed out scammers
I think this is a novel approach that does not exist on centralized appstore or play store. For instance @sommerfeld can submit an app repo for @Zapstore consideration, and review. Placeholder feature request: https://github.com/zapstore/zapstore/issues/13
Doesn't that still depend on zap.store repo maintainers approving a PR? Still centralized
Nevemind elsat, I misread your proposal!
But it would be cool to also include apps where their devs don't know/care about nostr. I was thinking of something like the Arch User Repository (AUR) where users submit packages that are not theirs and it's up to other users whether they trust it or not.