@jbz

This is from 2014. I think #flatpak basically fixes everything he's ranting about here (at least from the first two minutes I watched)

You should be able to use the apps and app stores that you trust without any gate keeping from your operating system. That’s a big part of why we chose to build our app store on @FlatpakApps

#Flatpak#AppCenter

alcinnz
alcinnz boosted

Another call out for help in the #Linux and #nixos community!

We REALLY want to get the #nixbook installer to be able to install #flatpak during (or right after) the calamares installation.

Currently its installing on first boot of nixbook, but it's janky, and causing some downstream issues.

I FEEL LIKE this should be fixable.

Again, the issue is that we want to install a handful of flatpaks after the nixos build, but it gets cranky with no DBUS.

https://github.com/mkellyxp/nixbook-installer/issues/4

Another call out for help in the #Linux and #nixos community!

We REALLY want to get the #nixbook installer to be able to install #flatpak during (or right after) the calamares installation.

Currently its installing on first boot of nixbook, but it's janky, and causing some downstream issues.

I FEEL LIKE this should be fixable.

Again, the issue is that we want to install a handful of flatpaks after the nixos build, but it gets cranky with no DBUS.

https://github.com/mkellyxp/nixbook-installer/issues/4

@Tutanota A stable, reliable #Tutamail#Flatpak!

The state of #Linux packaging seems to be a perpetual mess. There is no standard packaging format among distros (something that I don't think will be resolved any time soon) and I've always viewed third party packaging tools like #snap and #flatpak with skepticism, mainly from a #security perspective.

After reading this, I'd rather deal with the perpetual mess of different package managers than the unraveling security headache that is Flatpak.

https://www.linuxjournal.com/content/when-flatpaks-sandbox-cracks-real-life-security-issues-beyond-ideal

#tech #technews

The state of #Linux packaging seems to be a perpetual mess. There is no standard packaging format among distros (something that I don't think will be resolved any time soon) and I've always viewed third party packaging tools like #snap and #flatpak with skepticism, mainly from a #security perspective.

After reading this, I'd rather deal with the perpetual mess of different package managers than the unraveling security headache that is Flatpak.

https://www.linuxjournal.com/content/when-flatpaks-sandbox-cracks-real-life-security-issues-beyond-ideal

#tech #technews

During guadec someone was asking me how do we get flatpak-builder to work inside containers. I can't remember the handle/nickname of who it was, though I do remember the face, but the answer is that we are using a custom seccomp policy that we pass to podman/docker

Something like this:

--cap-drop all --security-opt seccomp=flatpak.seccomp.json

And the file is here: https://github.com/gnome-infra/ansible/blob/master/roles/gitlab-runner/files/flatpak.seccomp.json

#guadec #guadec2025 #flatpak

During guadec someone was asking me how do we get flatpak-builder to work inside containers. I can't remember the handle/nickname of who it was, though I do remember the face, but the answer is that we are using a custom seccomp policy that we pass to podman/docker

Something like this:

--cap-drop all --security-opt seccomp=flatpak.seccomp.json

And the file is here: https://github.com/gnome-infra/ansible/blob/master/roles/gitlab-runner/files/flatpak.seccomp.json

#guadec #guadec2025 #flatpak

alcinnz
alcinnz boosted

Why does @flathub not prominently show that a package is severely outdated for an architecture?

Something like "1 month ago" is not helpful if ONLY the ARM64 package has not been updated for four years.

I'll install that on my phone or laptop by accident and immediately have a security risk. Yes, that happened multiple times.

That's why I now read the issue tracker AND build manifest before installing any Flatpak packages.

Also, please cleanup abandonware.

#Flathub#Flatpak #security

Why does @flathub not prominently show that a package is severely outdated for an architecture?

Something like "1 month ago" is not helpful if ONLY the ARM64 package has not been updated for four years.

I'll install that on my phone or laptop by accident and immediately have a security risk. Yes, that happened multiple times.

That's why I now read the issue tracker AND build manifest before installing any Flatpak packages.

Also, please cleanup abandonware.

#Flathub#Flatpak #security