Flatsonar

Vertex Launcher

by SturdyFool10

Native Minecraft launcher written in Rust

Extensive permissions

About

Vertex Launcher is a native Minecraft launcher with Microsoft sign-in, multi-instance management, runtime provisioning, quick-launch flows, and integrated Modrinth and CurseForge browsing.

Permissions

6 permissions weaken the sandbox. Flatsonar asks before installing.

  • all devices (/dev): webcams, disks, raw hardware
    --device=all
  • X11 display: X11 lets apps read input and windows of other apps
    --socket=x11
  • access to operating-system files
    --filesystem=host-os:ro
  • full access to your home folder
    --filesystem=home
  • your keyring / saved passwords
    --talk-name=org.freedesktop.secrets
  • sets LD_LIBRARY_PATH: changes which libraries or plugins get loaded
    --env=LD_LIBRARY_PATH=/app/lib:/app/lib/GL/default/lib:/app/lib/GL/lib:/opt/rocm/lib:/opt/rocm/lib64:/opt/rocm/llvm/lib:/opt/cuda/lib64:/run/host/usr/lib:/run/host/usr/lib64:/run/host/usr/lib/x86_64-linux-gnu:/run/host/usr/lib/aarch64-linux-gnu:/run/host/usr/local/cuda/lib64:/run/host/lib:/run/host/lib64
  • Wayland display
    --socket=wayland
  • access to /opt/rocm
    --filesystem=/opt/rocm:ro
  • access to /opt/cuda
    --filesystem=/opt/cuda:ro
  • access to /run/udev
    --filesystem=/run/udev:ro
  • inter-process communication (needed for X11)
    --share=ipc
  • network
    --share=network
  • audio
    --socket=pulseaudio
  • access to xdg-config/vertexlauncher
    --filesystem=xdg-config/vertexlauncher
  • access to xdg-data/vertexlauncher
    --filesystem=xdg-data/vertexlauncher
  • access to xdg-cache/vertexlauncher
    --filesystem=xdg-cache/vertexlauncher
  • access to xdg-config/vertex-launcher
    --filesystem=xdg-config/vertex-launcher
  • access to xdg-run/gvfs
    --filesystem=xdg-run/gvfs
  • access to xdg-run/discord-ipc-0
    --filesystem=xdg-run/discord-ipc-0
  • access to xdg-run/discord-ipc-1
    --filesystem=xdg-run/discord-ipc-1
  • access to xdg-run/discord-ipc-2
    --filesystem=xdg-run/discord-ipc-2
  • access to xdg-run/discord-ipc-3
    --filesystem=xdg-run/discord-ipc-3
  • access to xdg-run/discord-ipc-4
    --filesystem=xdg-run/discord-ipc-4
  • access to xdg-run/discord-ipc-5
    --filesystem=xdg-run/discord-ipc-5
  • access to xdg-run/discord-ipc-6
    --filesystem=xdg-run/discord-ipc-6
  • access to xdg-run/discord-ipc-7
    --filesystem=xdg-run/discord-ipc-7
  • access to xdg-run/discord-ipc-8
    --filesystem=xdg-run/discord-ipc-8
  • access to xdg-run/discord-ipc-9
    --filesystem=xdg-run/discord-ipc-9
  • access to xdg-run/app/com.discordapp.Discord
    --filesystem=xdg-run/app/com.discordapp.Discord
  • access to xdg-run/app/dev.vencord.Vesktop
    --filesystem=xdg-run/app/dev.vencord.Vesktop
  • sets environment variable GDK_BACKEND
    --env=GDK_BACKEND=wayland,x11
  • sets environment variable OCL_ICD_VENDORS
    --env=OCL_ICD_VENDORS=
  • sets environment variable OPENCL_VENDOR_PATH
    --env=OPENCL_VENDOR_PATH=/app/lib/GL/lib/OpenCL/vendors
  • sets environment variable OCL_ICD_FILENAMES
    --env=OCL_ICD_FILENAMES=/opt/rocm/lib/libamdocl64.so:libnvidia-opencl.so.1
  • sets environment variable ROCM_PATH
    --env=ROCM_PATH=/opt/rocm
  • sets environment variable HIP_PATH
    --env=HIP_PATH=/opt/rocm
  • sets environment variable CUDA_PATH
    --env=CUDA_PATH=/opt/cuda
  • sets environment variable CUDA_HOME
    --env=CUDA_HOME=/opt/cuda

Who publishes this

Nobody has confirmed that the publisher controls this app id. Flatsonar warns before installing.

  • org.sturdyfool10.VertexLauncher claims the domain sturdyfool10.org; only its owner can prove that
    publisher:namespace
  • fetches from archive.ubuntu.com over unencrypted http: anyone on the path can swap the bytes (x4)
    source:insecure-url
  • installs a prebuilt binary instead of building from source (x4)
    source:prebuilt
  • the build has network access: it can download things the manifest does not list
    vertexlauncher:build-options:--share=network

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.