Flatsonar

FlatpakCommandValidator

by Murmele

Validation of flatpak commands

Dangerous permissions Verified creator GPL-3.0 v1.0.0
Screenshot 1 of FlatpakCommandValidator

About

Validation of flatpak commands lsdsdjdddddddddddddddddddddddddddd

Permissions

3 permissions weaken the sandbox. Flatsonar asks before installing.

  • sandbox escape: can run commands on the host via flatpak-spawn
    --talk-name=org.freedesktop.Flatpak
  • full access to your home folder
    --filesystem=home
  • your keyring / saved passwords
    --talk-name=org.freedesktop.secrets
  • Wayland display
    --socket=wayland
  • X11 display, only when Wayland is unavailable
    --socket=fallback-x11
  • notifications
    --talk-name=org.freedesktop.Notifications

Who publishes this

The creator demonstrably controls this app id: Flathub verification, the hosting account owns the namespace, or a well-known file on their domain.

  • git source tracks a moving branch: what gets built can change without the manifest changing
    source:unpinned
  • hosted by gitlab.com/murmele, which owns the com.gitlab namespace of com.gitlab.Murmele.FlatpakCommandValidator
    publisher:namespace

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.