3 ms·
It seems like 2) gets to the heart of what flatpak is and how it works. The argument in favor of traditional packaging over flatpak is that security vulns in de
by mapgrep 6y ago
It seems like 2) gets to the heart of what flatpak is and how it works. The argument in favor of traditional packaging over flatpak is that security vulns in dependencies get fixed for all packages at once. The architecture of flatpak allows / encourages package maintainers to update vulnerable dependencies at their leisure. The fact that this is observed in the wild in the linked article seems a natural consequence. What is the mechanism that would cause this behavior to change as the ecosystem matures?
- Iolaum 6y agoMore available resources to update dependencies and hopefully plug in CI/CD pipelines. Curated runtimes by appstore/OS vendors would also help. Also since most if not all the code/images is open source, automated vulnerability scanning. Using approaches from the docker ecosystem that faces the same problem would also help. All of the above however need resources (ie money) and that's why things are moving forward so slowly.