4 ms·
It's surprising that Flathub and Canonical's Snapcraft aren't involved in the Reproducible Builds initiative, since they're important distribution channels for
by codewiz 4y ago
It's surprising that Flathub and Canonical's Snapcraft aren't involved in the Reproducible Builds initiative, since they're important distribution channels for end-user applications that could read your ssh keys and wipe your hard-drive if the distribution chain is compromised.
- lrvick 4y agoThose projects were created because maintainers want things as easy as NPM because the traditional path requires care, signing, and process. Security was never the goal.
- Vogtinator 4y agoIMO you're exaggerating a bit, but there's quite some truth in there. Flatpak has some security features and is by itself not a bad design, but the ecosystem's current state isn't really utilizing those. Snap is a whole other can of worms. The ecosystem is like canonical's personal play store/app store.
- goodpoint 4y agoDespite the downvotes you are spot on.