Permissionless publishing update:
I received harsh criticism about the publishing experience lately, interestingly by some who genuflected before the centralized stores, but the feedback is valuable and made me rethink the whole process.
Publishing will have less friction, here's the medium-term plan:
1) Remove the relay.zapstore.dev whitelist. Pubkeys will be passed through a web-of-trust filter which should work for most profiles without asking for permission
2) Add relay management (will ship in Zapstore 1.1) such that app events can be hosted on any relay - now that a stable NIP has been defined
3) Create a tool to cryptographically link Android keystores with nostr pubkeys (NIP-39 PR). In this way, developers will only need to sign their kind 0, once. The Zapstore indexer will take care of pulling their app updates. (Downside: updates are not immediate as publishing directly)
