microsoft / microsoft/winget-pkgs

Publisher ownership / Verified Developer request: ownCloud GmbH (ownCloud.* packages)

Open
#408,277 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Issue-Feature
Dominant language
No language data
Stars
11.1k
Forks
9.7k
Avg merge
1h 32m
Merged PRs (30d)
616

Description

**Publisher Name:** ownCloud GmbH

**GitHub Account:** https://github.com/DeepDiver1975 (maintainer, ownCloud desktop client)

**Organization:** https://github.com/owncloud

**Package(s):**
- `ownCloud.ownCloudDesktop`
- `ownCloud.ownCloudDesktop.InfiniteScale`

**Proof of Ownership:**

I am a maintainer of the ownCloud desktop client at https://github.com/owncloud/client (the upstream project for these packages) and act here on behalf of ownCloud GmbH, the publisher named in the manifests. The installer URLs in every manifest point to `download.owncloud.com`, our own distribution host. I can provide any additional verification you need — a DNS TXT record on `owncloud.com`, a file served from `download.owncloud.com`, or confirmation from a company email address.

**Request:**

We would like to onboard as the verified publisher for the `ownCloud.*` package identifiers, so that submissions affecting these packages are attributable to us.

**Why we are asking now:**

Every ownCloud manifest to date has been submitted by third parties, not by us. That is normally fine and we appreciate the community's work. In this case it caused real user harm:

1. In #391930, `ownCloud.ownCloudDesktop` version `7.1.0.19041` was added by a third-party contributor. ownCloud 7.x is a client for **ownCloud Infinite Scale**, a different product line from the ownCloud Server that 5.x/6.x clients target — it is not a valid in-place upgrade for those users.
2. Because all our manifests since 5.3.1 share the MSI `UpgradeCode` `{EB15081D-1892-4DB5-872C-9424BFFFF22F}` with `UpgradeBehavior: install`, WinGet correlated installed 6.x products with the 7.1 manifest and performed unattended in-place major-version upgrades, including in managed/scheduled contexts. Administrators reported fleets of machines crossing that product boundary overnight, with Explorer being killed mid-session by the shell-extension swap (`InstallerSuccessCodes: 3010`).
3. #403418 correctly renamed 7.1 to `ownCloud.ownCloudDesktop.InfiniteScale`, but left the manifest in place under the original identifier, so the silent upgrades continue today. I have opened #408276 to remove it.

Full downstream investigation with Windows Installer event logs: owncloud/client#12581

Had we been able to review submissions against our own package identifiers, both the original mismatch and the incomplete rename would have been caught before shipping to users. Going forward we also intend to assign a distinct `UpgradeCode` to the Infinite Scale line in our WiX packaging so the two product lines can never be correlated again.

I saw in #360963 that the Verified Developer flow is currently limited to Microsoft packages and that a separate publisher onboarding process is planned. If that process is not yet open, please treat this as a request to be queued for it — and in the meantime, any way to flag these identifiers so that ownCloud is notified on incoming submissions would be very welcome.

Happy to follow whatever verification steps you prefer. Thanks for maintaining this repository.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review #360963 for the current Verified Developer flow and the repository context around publisher onboarding. Read #408276 and the linked owncloud/client#12581 investigation to understand the package-removal and ownership concerns. Done means deciding whether to establish an onboarding or notification path for ownCloud and documenting the required verification steps.

Written by the indexing model from the issue text.

Assessment

Domain
authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.