Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Richard Brown, who's been working on this problem for 10 years at Suse, says he was wrong in 2017. Flatpak is now the clear way to go, if you care about security, app updates, licensing, and multi-distro support (runtime dependencies).

https://ftp.fau.de/fosdem/2023/UA2.114%20(Baudoux)/container...



> security

Erm...

> we also reduce the ability for users to scrutinise the source in the Flathub build system that was used to build their application

I don't think so


Flatpak offers convenience but it could never offer the security that the distros it is circumventing offer. Application bundling is just inherently insecure.


He's still wrong.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: