Flatsonar

Podman Desktop

by Red Hat, Inc.

Manage Podman and other container engines from a single UI

Dangerous permissions Suspicious publisher Apache-2.0 v1.29.3
Screenshot 1 of Podman Desktop Screenshot 2 of Podman Desktop Screenshot 3 of Podman Desktop Screenshot 4 of Podman Desktop Screenshot 5 of Podman Desktop Screenshot 6 of Podman Desktop Screenshot 7 of Podman Desktop Screenshot 8 of Podman Desktop

About

Podman Desktop is an open source graphical tool enabling you to seamlessly work with containers and Kubernetes from your local environment.

Build, run and manage containers:

  • Build images from Containerfile or Dockerfile.
  • Pull images from remote registries.
  • Start, Stop, Restart containers and pods.
  • Easily get a terminal in your container.
  • Inspect container logs.
  • Push images to OCI registries.
  • Deploy and test images on Kubernetes.

Multiple configuration options

  • Manage OCI registries; add, edit, or delete registries.
  • Configure your proxy settings (work in progress.)
  • Configure CPU, memory, and disk of Podman machines (work in progress.)
  • Handle multiple container engines at the same time (Podman, Docker, Lima...)

You can also bring new features with Podman Desktop plug-ins or Docker Desktop extensions.

Permissions

6 permissions weaken the sandbox. Flatsonar asks before installing.

  • access to a sensitive location (/run/docker.sock): credentials or autostart
    --filesystem=/run/docker.sock
  • sandbox escape: can run commands on the host via flatpak-spawn
    --talk-name=org.freedesktop.Flatpak
  • X11 display: X11 lets apps read input and windows of other apps
    --socket=x11
  • full access to your home folder
    --filesystem=home
  • access to operating-system files
    --filesystem=host-os:ro
  • your keyring / saved passwords
    --talk-name=org.freedesktop.secrets
  • inter-process communication (needed for X11)
    --share=ipc
  • network
    --share=network
  • GPU acceleration
    --device=dri
  • access to xdg-run/podman
    --filesystem=xdg-run/podman:create
  • access to xdg-run/containers
    --filesystem=xdg-run/containers:create
  • system tray
    --talk-name=org.kde.StatusNotifierWatcher
  • notifications
    --talk-name=org.freedesktop.Notifications
  • talks to org.kde.kwalletd6
    --talk-name=org.kde.kwalletd6

Who publishes this

Something concrete is wrong: the id claims a namespace this repository does not own, or the build does things a build should not. Flatsonar warns twice.

  • decodes an embedded blob (hidden payload): sed -i -r -e "s/SEGMENT_KEY = '.*'/SEGMENT_KEY = '$(echo -n 'ODdEZUpwVFhmU05pemF5MUNxQXhsSzViYUQ4VUE1NUQ=' | base64 --de
    podman-desktop:build-commands
  • installs a prebuilt binary instead of building from source (x6)
    source:prebuilt
  • verified on Flathub: the developer proved they control this app id
    publisher:flathub

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.