Basically title.

I’m wondering if a package manager like flatpak comes with any drawback or negatives. Since it just works on basically any distro. Why isn’t this just the default? It seems very convenient.

  • danielfgom
    link
    fedilink
    English
    309 months ago

    It’s HUGE. That’s the biggest downside for me. I’m always use a deb/native package first because they are way smaller.

    • @hornedfiend@sopuli.xyz
      link
      fedilink
      159 months ago

      Of course they are. they share dependencies with other software. flatpaks bundle all dependencies,which is great for sandboxing,even though some sort of break the rule and share some,they are still sandboxed.

      Unless you “firejail” or “bubblewrap” your software, security is much better OOB for flatpaks.

      • @soFanzy@lemmy.world
        link
        fedilink
        119 months ago

        That’s a myth. Security of flatpaks depends entirely on the given permissions, and since most flatpaks just set their own permissions on installation, or require filesystem access to work, there is no meaningful difference in security OOB.

        • @wisha@lemmy.ml
          link
          fedilink
          69 months ago

          Flatpak apps cannot set their own permissions “on installation”. If flatpak tells you some weather app uses only the network permission then that is all the app is going to get.

          For an app to be able to change its own permissions, it first needs permission to the flatpak overrides directory. Any app that does this gets an “Unsafe” designation in gnome-software.

          Also about most apps requiring filesystem access to work: I have 41 flatpak apps on my system (Silverblue so everything is flatpak). Only 6 have access to my home or Documents directory. (11 apps requested full filesystem or homedir permission, but 5 of these work perfectly fine after I turned off their permissions in Flatseal).

          Notably, “large attack surface” apps like Thunderbird or Firefox don’t have access to my Documents. File uploads and email attachments go through the file picker portals.

      • @jabjoe@feddit.uk
        link
        fedilink
        English
        29 months ago

        Those dependencies adenoid and no kept Upton date, unlike deb/rpm installed stuff. Best sandbox to not compromise your system. Also hope that sandboxing is done right…