• GammaEnglish
    arrow-up
    3
    arrow-down
    0
    ·
    8 months ago
    edit-2
    8 months ago
    link
    fedilink

    You’re pretty much just rehashing a possible apt repo “vulnerability, but at least with flatpak they remember where each package was installed from.

      • GammaEnglish
        arrow-up
        3
        arrow-down
        0
        ·
        8 months ago
        link
        fedilink

        Anyone can create an apt repo and the override your system packages with new versions.

        At least with flatpak only the applications you installed from the bad actor’s repo would be affected, though obviously they can still have a ton of malicious dependencies

          • GammaEnglish
            arrow-up
            3
            arrow-down
            0
            ·
            8 months ago
            link
            fedilink

            I wasn’t trying to, just pointing out that it was nothing new