Flatsonar

Blaze Hub

by rudzik.tv

Your new GNOME appstore

Dangerous permissions Suspicious publisher GPL-3.0-or-later v0.0.0-alpha.dev.preview.4
Screenshot 1 of Blaze Hub Screenshot 2 of Blaze Hub Screenshot 3 of Blaze Hub

About

Blaze Hub is a GTK4 and LibAdwaita built application store, based on flathub. It might appear familiar to the GNOME Software, but there are a few more features and differences. - progress tab with network speed, (estimated) amount of downloaded data, (also estimated) total size to download - downloaded item also shows what packages it downloads - ability to choose between user's and system's installation - full-window screenshot preview on click, with ability to open in the ImageViewer

Permissions

5 permissions weaken the sandbox. Flatsonar asks before installing.

  • unrestricted access to the session D-Bus (all your running apps)
    --socket=session-bus
  • sandbox escape: can run commands on the host via flatpak-spawn
    --talk-name=org.freedesktop.Flatpak
  • full access to your entire file system
    --filesystem=host
  • development features (ptrace, can inspect other processes in its sandbox)
    --allow=devel
  • access to operating-system files
    --filesystem=host-os
  • X11 display, only when Wayland is unavailable
    --socket=fallback-x11
  • Wayland display
    --socket=wayland
  • GPU acceleration
    --device=dri
  • network
    --share=network
  • inter-process communication (needed for X11)
    --share=ipc
  • access to /var/lib/flatpak/app
    --filesystem=/var/lib/flatpak/app
  • access to /var/lib/flatpak
    --filesystem=/var/lib/flatpak
  • access to ~/.local/share/flatpak
    --filesystem=~/.local/share/flatpak
  • access to ~/.local/share/flatpak/app
    --filesystem=~/.local/share/flatpak/app
  • access to ~/.local/share/flatpak/exports/share/icons
    --filesystem=~/.local/share/flatpak/exports/share/icons
  • access to /var/lib/flatpak/exports/share/icons
    --filesystem=/var/lib/flatpak/exports/share/icons
  • sets environment variable FLATPAK_CMD
    --env=FLATPAK_CMD=/run/host/bin/flatpak
  • sets environment variable DOTNET_ROOT
    --env=DOTNET_ROOT=/app/lib/dotnet

Who publishes this

Something concrete is wrong: the id claims a namespace this repository does not own, or the build does things a build should not. Flatsonar warns twice.

  • io.github.flamedev.blazehub claims the io.github.flamedev namespace but is hosted by github.com/rudziktv and does not build the owner's code
    publisher:namespace

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.