Sweeping package management problems under a rug doesn't actually make them go away.
Sweeping package management problems under a rug doesn't actually make them go away.
Anybody have a list of open source solutions here?
This has a level of indirection, but that just delays things until the next login. With a little more work there are infinite other places you could inject that might run sooner.
Yeah, that's like the poster child of sandboxing; I am very much supposing that my word processor is not allowed to touch arbitrary files.
RHEL RPMs are signed by Red Hat. Flatpaks are signed by... whoever happens to maintain that flatpak.
But at any rate the multiple runtimes with multiple upstreams are why it's a non-starter from a security PoV; the uselessness of sandboxing is more just icing.
Realistically, I know that I do not have the skills to evaluate complicated applications and their complicated dependencies for security characteristics, so I am 100% reliant on packagers, maintainers, etc. for my security anyway. I'd rather just donate to the people publishing and maintaining the packages and hope that they are doing the job well, than fruitlessly attempt to fuss over it myself.
The good news is there is a solution to this. The trusted system shows a file picker, and then grants access to the sandboxes application.
This is called the File Chooser Portal. https://docs.flatpak.org/en/latest/portal-api-reference.html...
I suppose additional security features inspired by mobile systems couldn't hurt either. Like a pop-up whenever something accesses the clipboard.
I just hope flatpak sandboxing works well...
Besides, why 2 KDE AND 2 Gnome versions would be needed. The 'minimal' freedesktop would most likely suffice.
Now, it's possible to build my own flatpaks and keep everything updated, but if I'm doing that I might as well just build the actual software and use the distro's package management system.