4 ms·
Because I can finally download the same file and run it on my distro of choice without installing it as a system package. This is not a replacement for traditio
by amlib 10y ago
Because I can finally download the same file and run it on my distro of choice without installing it as a system package. This is not a replacement for traditional linux packages. It has it's own set of advantages and disadvantages. This may lead to a good solution for app support fragmentation on linux.
- digi_owl 10y agoGood? This is the devops container boys recreating Windows' DLL hell and selling it as an "improvement". If you want to run something without installing it as a distro package the option was always to download it as a tar-ball. BTW, Flatpak is a Gnom/freedesktop creation. It is a reaction to distro maintainers overriding the "perfect" decisions made by upstream (Gnome devs etc), and is upstreams attempt at taking over control. Gnome+Freedesktop is aiming to make a singular Linux desktop experience, for all the wrong reasons.
- colemickens 10y ago>This is the devops container boys recreating Windows' DLL hell and selling it as an "improvement". I'm not a fan of Flatpak (Nix/Guix for the win), but this is completely incorrect.
- digi_owl 10y agoHow so? You have a limited option to outsource what you bundle via "frameworks", but that concept only go so deep. You can bet your behind that if the format ever takes off, every flatpak will contain their own copy of libc on up just to be sure. This similar to how every Windows program ship with a VC++ DLL bundle, just to be sure.
- colemickens 10y agoI guess I misinterpreted what you meant by "DLL hell" then.
- lisivka 10y agoSo how you plan to fix security holes in flatpak aps, please? Static bundling predates UNIX. It's long known nightmare. New developers are not familiar with static bundling, so they thinking that they are «moving forward».
- colemickens 10y agoThe same way you solve this anyway, or the same answer you should hear when people say "how do you handle security with Docker": Continuous Integration.
- lisivka 10y agoCI and maintenance are different things. AFAIK, it's recommended to pin versions of libraries, not to update libraries at every integration, so security fixes will be delayed. Moreover, developers never release new version of an app when a dependency is updated only, while maintainers do. It's called bit rot.
- colemickens 10y agoTake NixOS as an example. When libc gets a security fix, everything is automatically rebuilt and binary cache packages are available for users.
- lisivka 10y agoIt's waste of resources. Fedora does mass rebuild once per 3 months at average. If libc gets a security fix, dnf in Fedora will download just a delta between packages. Lower consumption of resources mean faster turn-over rate and is better overall. But I can mimic NixOS behavior with mock (tool for clean rebuilds) and chroots or containers, if I want.