this post was submitted on 15 Feb 2025
189 points (98.5% liked)

Linux

6067 readers
414 users here now

A community for everything relating to the GNU/Linux operating system

Also check out:

Original icon base courtesy of [email protected] and The GIMP

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 15 points 6 days ago (2 children)
[–] corsicanguppy 1 points 6 days ago

Former Unix security lead here, with a build/release background.

Completely insecure in the "I think the doors are locked but I can't check and didn't check and they told me it was okay but I don't know why they are" way. It has absolutely no validation with the rest of the system and fails "how do we know" after about 3 iterations.

Downvote people who aren't flying the right flag - you be you - but maybe one day look into this.

[–] [email protected] 0 points 6 days ago (1 children)

It doesn't have package signing. The source is their documentation.

[–] [email protected] 10 points 6 days ago (1 children)

flatpak build-sign, is what I can find in the documentation.