5 ms·
If Microsoft officially starts publishing their apps to Flathub then we could have a watershed moment for Flatpak adoption. One central app store for Linux. Pus
by moojacob 5y ago
If Microsoft officially starts publishing their apps to Flathub then we could have a watershed moment for Flatpak adoption. One central app store for Linux. Pushing Microsoft to take over maintaining the Flatpak for Edge is only a good thing? HN should be supporting the Edge authors.
Flatpak is really special technology. Joy to package, excellent end user experience, and completely open.
- thaumasiotes 5y ago> we could have a watershed moment for Flatpak adoption. One central app store for Linux. Because that model worked so well for iOS and Android?
- judge2020 5y agoDepends on how you define worked well. iOS and Android are immensely successful on providing value to users on the UX front (think of how many smartphone users would have a hard time downloading and installing eg. 7-zip).
- Spivak 5y agoYou mean the packaging ecosystems that are so wildly successful they’re used by essentially 99.76% of smartphone users and 99.97% of tablet users? I think it worked out pretty well tbh. Would be an odd choice not to copy the model.
- akvadrako 5y agoIt's not the same thing. Flatpak allows multiple remotes so anyone can publish their own packages.
- fiddlerwoaroof 5y agoThe point of picking a Linux distribution is buying into a package management scheme. If you want to pick the “flatpak” distro fine, but I’m sticking with apt or nix
- Spivak 5y agoThis purposely ignores that Flatpak is designed to be hosted on existing distros like pip, gem, docker, nix, guix, snap, etc. etc.
- johnny22 5y agothat's "one point" of picking a distribution. Another is cadence, and trust in the people who make it. There are also the organization considerations. Debian has both the Debian Constitution and the Debian Social Contract. Those aren't things every distro has. (These aren't the only other points, just ones off the top of my head)
- lokedhs 5y agoFlatpak is the only packaging system that takes even a tiny step towards trying to give you some kind of security. When installing software using any other packaging system you have no isolation what so ever. The software is able to help to do anything on the system as root (because the installer script runs as root). Not even Nix, which is supposed to give you some kind of reproducibility helps. I personally don't trust every single software developer with the integrity of my entire computing environment. I want the code I run to be isolated and only be able to access the things they are supposed to be able to access. Now, there are valid concerns that Flatpak doesn't provide enough isolation, and that it's never really clear what rights a given package actually has, forcing you to use Flatseal to manually configure the rights for packages. However, no other packaging system does anything to address the terrible security situation on Linux, so there is really no other alternative. Well, there is one alternative which I generally recommend people to use which is Qubes OS, but it takes quite a bit of discipline to use it correctly, so it's not practical for all users.
- mindwok 5y agoIt’s more nuanced than that. Most of the major distributions provide the packages and hence the install scripts (the part which runs as root) and if you don’t trust them then you shouldn’t be running their Linux distribution. Once most software is installed it will run unprivileged, and in most cases will be even further restricted by selinux, app armour, and/or systemd.
- smoldesu 5y ago> Flatpak is really special technology. Joy to package, excellent end user experience, and completely open. Are we even using the same software? That has not been my experience at all.
- Gigachad 5y agoI used flatpak extensively and every issue I had was the result of software being repackaged by a 3rd party and the contained software not properly interacting with the flatpak apis. Stuff that was natively designed for flatpak was flawless while other stuff had some minor issues when it expects things like direct file system access or expects libraries to just exists on the fs rather than explicitly bundling them in or requesting them.