Germany's Sovereign Tech Agency invests €508,640 in Flatpak

Sovereign Tech Agency invests €500k in Flatpak

Germany's Sovereign Tech Agency invests €508,640 in Flatpak

The Sovereign Tech Agency is funding a two-year project to improve Flatpak's sandboxing and security. The initiative, co-organized by Modal, will add new portals for audio, network, VPN, spell checking, and password auto-fill, plus infrastructure like entitlements and intents. The goal is to close gaps that trail behind Android and iOS, enhancing the security of Linux desktop ecosystems.

Flatpak is a mature project and the best option that exists on GNU/Linux today, but its security and sandboxing features still trail behind those of well-funded proprietary platforms such as Android and iOS.
  1. ho_schi

    I’m thankful for the STF. Germany is one of the few countries doing something. But it is not strategic software-development.

    * They don’t employ software-developers. No safety for the developers. No control over developers.

    * It is only temporary.

    * The projects need to apply repeatingly for funding. Wasting time and resources and chausing worries.

    The how planet needs Linux, BSD, cURL, ffmpeg, Flatpak. We need to ensure that this work for the people.

    We feed for 30 years constantly money into monopolies. We shall feed the next century constantly money into things the people need.

    Many developers of Linux and GCC are paid. Because companies decided it is necessary.

  2. TekMol

    I never understood why a program installed in Flatpak is not just a directory on disk.

    When you install something via Flatpak, it still changes data in god-knows-what places on my disk. And the software itself has read/write access to god-knows-where on my disk.

    The answer is probably "convenience and efficiency". But I would much prefer a "An application is a directory and by default cannot access anything outside of that directory" approach.

  3. EffrafaxOfWug

    I avoid flatpaks and snaps as much as I can.

    Here is a little blog post from 2021 that lists some of the huge issues flatpaks have

    https://ludocode.com/blog/flatpak-is-not-the-future

    If you want to sandbox your programs highly recommend looking at firejail.

  4. j1elo

    I loved Flatpak until I started building a MiniPC with a 112 GB internal disk for HTPC usage... Then I felt the pain of having to get all slightly different dependency versions for each little program I wanted.

    The box' cost already topped the project's budget so no new disk for it. I'm back to "proper .deb packaging please"

  5. robin_reala

    The Soverign Tech Agency are currently hiring for a Director of Technology. Definitely a dream job for someone. https://www.sovereign.tech/jobs/director-of-technology

  6. minimeow

    My trust in Flatpak diminished after installing the book reader Calibre and finding that despite the sandboxing Calibre was given blanket access to my drive. Apparently a quirk of the developer behind Calibre insisting upon it. No warnings or communication of the exception were given. All trust I had in Flatpak was eroded from that moment on. Curious about the podman options or similar. Having desktop apps in a container with selective access to system resources seems like it would be more secure and configurable if configured correctly. Flatpak as it stands seems to be a legacy solution to what should be a container and namespacing solution.

  7. sdcfgy

    I'd rather they invested €500k in contributing to the maintenance of distribution packages so I don't need to deal with Flatpak (on Debian here).

  8. regexorcist

    I use bubblewrap directly, never liked Flatpak.

More from this day

2026-08-28