{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreidqz3g3js65lmvqu6at5s34pgus4bczo2l6f7bm3vdevw4jphvyhu",
"uri": "at://did:plc:yrn4rbgwenb6lfhhzjegbtnc/app.bsky.feed.post/3mjc6dmjpw4t2"
},
"path": "/t/security-of-unverified-flatpaks/11983#post_6",
"publishedAt": "2026-04-12T09:23:39.000Z",
"site": "https://discourse.flathub.org",
"tags": [
"Basic concepts - Flatpak documentation",
"Sandbox Permissions - Flatpak documentation"
],
"textContent": "The first question is very technical; I wish there were detailed documentation pages to answer your question. Here’s what I could find:\n\n * Basic concepts - Flatpak documentation\n * Basic concepts - Flatpak documentation\n * Sandbox Permissions - Flatpak documentation\n\n\n\nSecond question:\n\nEven modified source code must use the same sandbox permissions. Otherwise, some major changes made to the manifest file will automatically trigger certain alarms, and the application will not be released. We also track changes made to the manifest file. I wish there was a restriction preventing changes to the main repository. Sometimes applications change repository names, sometimes developers change usernames, and there is currently no strict restriction against changing the main repository URL.\n\nI couldn’t find any documentation to link to regarding the last question.\n\nThat’s all the information I have. I didn’t want to just paste an AI-generated answer.\n\n/Google Translate",
"title": "Security of unverified flatpaks"
}