5 ms·
> One thing I don't know about (which maybe somebody can inform me/us about): the wiki states that PRs are reviewed by Flathub reviewers, but I see no sign of h
by orra 3y ago
> One thing I don't know about (which maybe somebody can inform me/us about): the wiki states that PRs are reviewed by Flathub reviewers, but I see no sign of human review on e.g. https://github.com/flathub/com.bitwarden.desktop/pull/167 https://github.com/flathub/com.bitwarden.desktop/pull/167 (or others in that repo). What's the actual process?
In this case, I think the lack of human involvement is mostly a good thing. Flathub was criticised for having outdated packages[1]. Using automation to automatically update packages is mostly a good thing.
Obviously, we want to see thorough review of new packages, but that's a separate issue.
[1] I thought I read this in an LWN article, but I can't find it. But see e.g. https://github.com/flathub/org.qutebrowser.qutebrowser/issues/8 https://github.com/flathub/org.qutebrowser.qutebrowser/issue...
- smallerfish 3y ago> Using automation to automatically update packages is mostly a good thing. Maybe. The CI rules should be made public in that case, though, surely? Maybe they are? The enormous amount of value the distros bring (aside from sponsorship of the ecosystem) is audit of packages (and packaging). If we want to move application packaging away from the distros, Flathub needs to be at least as competent in its process, automated or not.
- orra 3y ago> Maybe. The CI rules should be made public in that case, though, surely? Maybe they are? Agreed, but thankfully they are. The PRs link to <https://github.com/flathub/flatpak-external-data-checker https://github.com/flathub/flatpak-external-data-checker>. That said, it'd be clearer if the flathubbot 'user' profile also linked to that URL. > The enormous amount of value the distros bring [...] is audit of packages (and packaging). Yes, auditing against supply chain attacks is good! But there's also a risk in running outdated software. I don't have easy answers. But if automation leaves more time for the hard part, great.
- smallerfish 3y agoMaybe unfair to ask you (but thanks for the helpful answers so far). Is there a check for "this distribution comes from the official source"? Let's say some state actor compromises taaem's desktop computer, and changes the url in the manifest to (say) https://githսb.com/bitwarden/clients/releases/download/desktop-v2023.10.1/Bitwarden-2023.10.1-amd64.deb https://xn--githb-bjg.com/bitwarden/clients/releases/downloa... (that's a unicode lookalike ս in there, which in github at least renders without expansion as "github.com" - HN is smart enough to expand it), or something equally nefarious. CI's not going to catch that, right? And nobody's actually paying attention to changes?
- orra 3y agoNot an expert, but unfortunately I think you're right in identifying a potential attack vector with the Flathub maintainership model. Even if flathubbot is being used, manual changes can still be made by maintainers. And I think there are far more maintainers to trust, than for say scoop or winget. The difference is, Flathub has one repo per package (and hence allows more maintainers).