Flatpak Trust and Transparency

I believe Flatpak is the easiest way to get packages not available in official or common third party repositories, and I love that. But I also don’t know who uploaded and created the package, unless it has that blue verified checkmark. I don’t know who is maintaining it or if anything untoward has happened

In short we need a reputation system or at least for the individuals uploading and upkeeping these packages to be known entities on the page. I should be able to see “Maintained and uploaded by X/Y/Z” and for their github or whatever they use to be linked to it.

For instance, there is Path of Building Community. This Flatpak doesn’t tell me who it is maintained by, only that it’s unverified. I don’t know what kind of checks and verifications go on in the background, I know a lot of people use Flathub, but at the very least, the uploader and maintainers should have some kind of presence on the page, especially for Flatpaks which are NOT maintained and uploaded by their originator. those I have a lot less problems with.

It’s just better for everyone involved, especially the end users.

Did you have a look at this recent topic which seems to address your question?

I didn’t see it before I posted, no. but if it’s this common of a request and a concern, it should be a priority to add, no? i mean I assume the people who maintain the different packages here are known to the site, would take very little to just push that information to the public listing for the listing would it not?

hey! I’m just the messenger
:innocent:

Since the information is already available & accessible to all, you can (& I personally would) argue that it’s not really a priority issue.

Flathub is an open-source project: Flathub Infrastructure · GitHub

Most likely the maintainers will be happy if you provide a concept with a pull-request yourself.

An issue already exists & the data doesn’t seem to be easily / automatically available: Add a "Packaged by" field · Issue #3125 · flathub-infra/website · GitHub

1 Like

It was already answered, but it’s already possible to check the contributors of a project.

Click on Manifest link to open the Flathub repo (repo related to make the app available in Flathub)

Click on Commits or Activity to see the last contributions (and its authors)
Or Contributors to see all the contributors of the project