Flatsonar

Atomic Image Manager

by Atomic Image Manager Contributors

Manage atomic/ostree system images

Dangerous permissions Suspicious publisher GPL-3.0-or-later v3.0.0
Screenshot 1 of Atomic Image Manager Screenshot 2 of Atomic Image Manager Screenshot 3 of Atomic Image Manager

About

Atomic Image Manager provides a modern graphical interface for managing atomic/ostree-based system images. It supports Fedora Silverblue, Kinoite, and Universal Blue variants, providing a safe, guided experience for system image operations. The application is designed for users of atomic systems including Fedora Silverblue, Kinoite, and Universal Blue images (Bluefin, Aurora, Bazzite, etc.) who want a user-friendly way to rebase between different image variants or rollback to previous deployments. Key Features: - Visual system status monitoring with real-time rpm-ostree integration - Safe rebase operations with confirmation dialogs and progress tracking - Deployment history and rollback capabilities - Modern libadwaita interface with responsive design - Comprehensive error handling and recovery guidance - Support for Fedora atomic and Universal Blue image variants - Demo mode for non-ostree systems The application requires an rpm-ostree-based system (like Fedora Silverblue, Kinoite, or any Universal Blue image) for full functionality. On other systems, it runs in demo mode to showcase the interface and features.

Permissions

7 permissions weaken the sandbox. Flatsonar asks before installing.

  • sandbox escape: can run commands on the host via flatpak-spawn
    --talk-name=org.freedesktop.Flatpak
  • access to operating-system files
    --filesystem=host-os:ro
  • access to operating-system files
    --filesystem=host-etc:ro
  • systemd: can manage services
    --talk-name=org.freedesktop.systemd1
  • session management (logout, suspend)
    --talk-name=org.freedesktop.login1
  • authorisation (polkit)
    --talk-name=org.freedesktop.PolicyKit1
  • authorisation (polkit)
    --system-talk-name=org.freedesktop.PolicyKit1
  • inter-process communication (needed for X11)
    --share=ipc
  • X11 display, only when Wayland is unavailable
    --socket=fallback-x11
  • Wayland display
    --socket=wayland
  • GPU acceleration
    --device=dri
  • access to /run/host/etc
    --filesystem=/run/host/etc:ro
  • access to /var/log
    --filesystem=/var/log:ro
  • access to /proc
    --filesystem=/proc:ro
  • access to /sys
    --filesystem=/sys:ro
  • access to /usr/bin/rpm-ostree
    --filesystem=/usr/bin/rpm-ostree:ro
  • access to /usr/libexec/rpm-ostree
    --filesystem=/usr/libexec/rpm-ostree:ro
  • talks to org.projectatomic.rpmostree1
    --talk-name=org.projectatomic.rpmostree1
  • portal Desktop
    --talk-name=org.freedesktop.portal.Desktop
  • portal NetworkMonitor
    --talk-name=org.freedesktop.portal.NetworkMonitor
  • portal MemoryMonitor
    --talk-name=org.freedesktop.portal.MemoryMonitor
  • portal Settings
    --talk-name=org.freedesktop.portal.Settings
  • portal Flatpak
    --talk-name=org.freedesktop.portal.Flatpak
  • network
    --share=network

Who publishes this

Something concrete is wrong: the id claims a namespace this repository does not own, or the build does things a build should not. Flatsonar warns twice.

  • io.github.ublue.RebaseTool claims the io.github.ublue namespace but is hosted by github.com/ulilbagel and does not build the owner's code
    publisher:namespace

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.