Central list of Flatpak repositories?

Sébastien Wilmet swilmet at gnome.org
Mon Aug 21 18:26:17 UTC 2017


On Mon, Aug 21, 2017 at 08:55:14AM +0200, Alexander Larsson wrote:
> I can see two ways such a thing could be done. Either one can be very
> very careful about what is put on the list, with careful review of
> everything and hard rules about how the repos should work. This is
> really is just a way to reproduce flathub with multiple actual repos.

Yes I was thinking more that way, to review new repos/apps. To do a
little like what Linux distros currently do, but instead of doing it
downstream (and duplicated for each distro), doing it upstream.

> The other way is to be very inclusive and add everyone who asks.
> However, then you can have zero trust in anything that comes from this.
> Anyone could put malicious forks, trojans or just poorly maintained
> repos to it, putting all users at risk.

Maybe in the future, when all the apps will be well sandboxed.

> There has been some discussions in allowing (e.g.) the flathub repo to
> "contain" an app in another repo (a form of redirect), in case some
> upstream has an official repo which the flathub organization has enough
> trust in. This would essentially implement the first approach above.
> However these were just loose discussions, there is no code that
> supports this.

The redirect seems a good idea.

--
Sébastien


More information about the Flatpak mailing list