Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)J
Posts
15
Comments
391
Joined
2 yr. ago

  • chat is this real (as in the actual line)

  • Text files could theoretically contain malicious content. Why doesn't the format have a built-in virus scanner??? Is this what you're suggesting?

  • Flathub has manual submission verification though, which includes the steps to build flatpaks. Reviewers (currently) would definitely catch fishy looking apps.

    They've also implemented manual reviews in case of metainfo or flatpak permission changes, another thing for additional safety.

  • Those are just app distribution formats. Since there's just 1 snap store which can deliver snaps, they're not comparable.

  • Reddit gold ⁉️⁉️😨😨😨🥰🥰🥰🥰🥰🥰🥰🥰🥰🥰🥰

  • That doesn't mean it constantly requires a mesa git snapshot.

  • There's the org.freedesktop.Platform.GL{,32}.mesa-git runtime(?) so that seems wrong. What app always needs the latest snapshot mesa version anyway?

  • uses its own libraries and not system libraries, want to play the hit new AAA game with steam flatpak? get fucked it requires a mesa commit that was merged 8 hours a go and you're stuck on 23.0.4 and can't use the git release.

    Can't you just install a git snapshot of mesa in a flatpak and use that? Then it'd be an upside

  • Isn't that just like it is on Cisco systems?

  • That's still not the same as impersonating a known app or developer though

  • Since you need to pass a manual review during initial submission of the app, no, you can't

  • Flathub has manual reviews during initial submission though. Also they're working on automatically needing a manual review when e.g. new permissions are granted to apps

  • Guess what, the local private translations feature depends on AI/ML. All this blind hate for AI is so stupid.

  • Wouldn't rootless containers have reduced the impact of these vulnerabilities? I'll happily continue using rootless podman for simple tasks

  • hi confusion