1

Does the flatpak package manager in Fedora-based systems require successful cryptographic authentication and integrity validation for all packages?

I know that software downloaded with apt-get packages must be cryptographically verified because the repo's manifest files (synced with apt-get update) are cryptographically signed.

But what about flatpak?

Do Operating Systems with flatpak require valid signatures from a pinned set of keys on all packages by default?

3

1 Answer 1

1

No. As of 2023, flatpak does not provide cryptographic authentication on any of the packages it downloads.

This was originally submitted as a feature request in 2015, but the devs either don't understand the security risk or they don't care enough about security to implement it.

You must log in to answer this question.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.