Flatsonar
Suspicious publisher

NanoVNASaver

by The NanoVNA-Saver Authors

View and export Touchstone data from a NanoVNA radio network tester device

Extensive permissions Suspicious publisher
Screenshot 1

About

The NanoVNA device is a vector network analyzer and antenna analyzer, useful to test or instrument various kinds of radio networks. NanoVNA-saver imports Touchstone files from the NanoVNA, sweeps frequency spans in segments to gain more than 101 data points, and generally displays and analyzes the resulting data.

Permissions

1 permission weaken the sandbox. Flatsonar asks before installing.

  • all devices (/dev): webcams, disks, raw hardware
    --device=all
  • inter-process communication (needed for X11)
    --share=ipc
  • Wayland display
    --socket=wayland
  • X11 display, only when Wayland is unavailable
    --socket=fallback-x11
  • access to your documents folder
    --filesystem=xdg-documents

Who publishes this

Something concrete is wrong: the id claims a namespace this repository does not own, or the build does things a build should not. Flatsonar warns twice.

  • io.github.zarath.nanovna-saver claims the io.github.zarath namespace but is hosted by github.com/nanovna-saver and does not build the owner's code
    publisher:namespace
  • git source tracks a moving branch: what gets built can change without the manifest changing
    source:unpinned
  • the build has network access: it can download things the manifest does not list
    build-options:--share=network
  • fetches from the network during the build (nothing to audit beforehand): pip install --prefix=/app uv
    uv:build-commands
  • fetches from the network during the build (nothing to audit beforehand): pip install --prefix=/app dist/NanoVNASaver*whl
    nanonva-saver:build-commands

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.