shady
by heyjuvi
A GTK+ shader editor, that aims for Shadertoy.com compatibility (and more…)
Extensive permissions
Looks abandoned
About
A GTK+ shader editor, that aims for Shadertoy.com compatibility (and more…)
Permissions
9 permissions weaken the sandbox. Flatsonar asks before installing.
- sandbox escape: can run commands on the host via flatpak-spawn
--talk-name=org.freedesktop.Flatpak - full access to your entire file system
--filesystem=host - development features (ptrace, can inspect other processes in its sandbox)
--allow=devel - X11 display: X11 lets apps read input and windows of other apps
--socket=x11 - full access to your home folder
--filesystem=home - authorisation (polkit)
--system-talk-name=org.freedesktop.PolicyKit1 - dconf: all GNOME settings
--talk-name=ca.desrt.dconf - package management
--talk-name=org.freedesktop.PackageKit - your keyring / saved passwords
--talk-name=org.freedesktop.secrets - inter-process communication (needed for X11)
--share=ipc - GPU acceleration
--device=dri - audio
--socket=pulseaudio - Wayland display
--socket=wayland - network
--share=network - access to xdg-run/dconf
--filesystem=xdg-run/dconf - access to ~/.config/dconf
--filesystem=~/.config/dconf:ro - sets environment variable DCONF_USER_CONFIG_DIR
--env=DCONF_USER_CONFIG_DIR=.config/dconf - talks to org.freedesktop.FileManager1
--talk-name=org.freedesktop.FileManager1 - talks to org.gnome.SettingsDaemon.Color
--talk-name=org.gnome.SettingsDaemon.Color - access to xdg-run/keyring
--filesystem=xdg-run/keyring - sets environment variable SSL_CERT_DIR
--env=SSL_CERT_DIR=/etc/ssl/certs - access to /etc/ssl
--filesystem=/etc/ssl:ro - access to /etc/pki
--filesystem=/etc/pki:ro - access to /etc/ca-certificates
--filesystem=/etc/ca-certificates:ro - access to ~/.local/share/flatpak
--filesystem=~/.local/share/flatpak - access to /var/lib/flatpak
--filesystem=/var/lib/flatpak
Who publishes this
Nobody has confirmed that the publisher controls this app id. Flatsonar warns before installing.
- org.hasi.shady claims the domain hasi.org; only its owner can prove that
publisher:namespace - git source tracks a moving branch: what gets built can change without the manifest changing (x3)
source:unpinned - fetches from github.com over unencrypted git: anyone on the path can swap the bytes
source:insecure-url
Maintenance
The upstream repository is archived, or has had no commits in several years.
- no commits in over 5 years
maintenance:stale