Ungoogled Chromium
by imput
internet, but lighter
About
Bullshit-free web browser, based on Chromium. Follows imput's ethics and norms. Very WIP, not meant for public/end user consumption, etc. First and foremost, we're making a good browser for ourselves. We don't intend to reinvent the wheel or target everyone, it isn't Helium's goal. The main goal is to provide an honest, comfortable, privacy-respecting, and non-invasive experience. If you don't like it - you don't like it, that's totally okay, and we don't care. There's a lot more to Helium, but we don't have a complete set of features yet. We'll update the documentation when we're closer to a public release!
Permissions
10 permissions weaken the sandbox. Flatsonar asks before installing.
- all devices (/dev): webcams, disks, raw hardware
--device=all - smart card readers
--socket=pcsc - X11 display: X11 lets apps read input and windows of other apps
--socket=x11 - talks to system service org.bluez
--system-talk-name=org.bluez - talks to system service org.freedesktop.Avahi
--system-talk-name=org.freedesktop.Avahi - your keyring / saved passwords
--talk-name=org.freedesktop.secrets - access to unrecognised path 'home/.local/share/applications:create'
--filesystem=home/.local/share/applications:create - access to unrecognised path 'home/.local/share/icons:create'
--filesystem=home/.local/share/icons:create - dconf: all GNOME settings
--talk-name=ca.desrt.dconf - sets GIO_EXTRA_MODULES: changes which libraries or plugins get loaded
--env=GIO_EXTRA_MODULES=/app/lib/gio/modules - require-version 1.8.2
--require-version=1.8.2 - inter-process communication (needed for X11)
--share=ipc - network
--share=network - printing
--socket=cups - audio
--socket=pulseaudio - Wayland display
--socket=wayland - Bluetooth
--allow=bluetooth - battery status
--system-talk-name=org.freedesktop.UPower - talks to com.canonical.AppMenu.Registrar
--talk-name=com.canonical.AppMenu.Registrar - talks to org.freedesktop.FileManager1
--talk-name=org.freedesktop.FileManager1 - notifications
--talk-name=org.freedesktop.Notifications - screensaver inhibit
--talk-name=org.freedesktop.ScreenSaver - talks to org.kde.kwalletd5
--talk-name=org.kde.kwalletd5 - talks to org.kde.kwalletd6
--talk-name=org.kde.kwalletd6 - session inhibit
--talk-name=org.gnome.SessionManager - talks to org.gnome.ScreenSaver
--talk-name=org.gnome.ScreenSaver - talks to org.gnome.Mutter.IdleMonitor.*
--talk-name=org.gnome.Mutter.IdleMonitor.* - talks to org.cinnamon.ScreenSaver
--talk-name=org.cinnamon.ScreenSaver - talks to org.mate.ScreenSaver
--talk-name=org.mate.ScreenSaver - talks to org.xfce.ScreenSaver
--talk-name=org.xfce.ScreenSaver - registers as a media player (MPRIS)
--own-name=org.mpris.MediaPlayer2.chromium.* - access to /run/.heim_org.h5l.kcm-socket
--filesystem=/run/.heim_org.h5l.kcm-socket - access to xdg-run/pipewire-0
--filesystem=xdg-run/pipewire-0 - access to your desktop folder
--filesystem=xdg-desktop - access to your download folder
--filesystem=xdg-download - access to /tmp
--filesystem=/tmp - keeps .pki between runs
--persist=.pki - access to xdg-run/dconf
--filesystem=xdg-run/dconf - access to ~/.config/dconf
--filesystem=~/.config/dconf:ro - sets environment variable DCONF_USER_CONFIG_DIR
--env=DCONF_USER_CONFIG_DIR=.config/dconf - sets environment variable GSETTINGS_BACKEND
--env=GSETTINGS_BACKEND=dconf - access to ~/.config/kioslaverc
--filesystem=~/.config/kioslaverc
Who publishes this
Nobody has confirmed that the publisher controls this app id. Flatsonar warns before installing.
- packaged by github.com/dopreo, not by the io.github namespace owner; it does build the owner's code from https://github.com/imputnet/helium-chromium
publisher:namespace - same name as io.github.ungoogled_software.ungoogled_chromium on Flathub but from a different repository
publisher:lookalike
Maintenance
Recent activity on the upstream repository, or built and reviewed by Flathub.
No staleness signals: recent activity, or built and reviewed by Flathub.