TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Flatpak builds are not reproducible and why that's a practical problem (2022)

34 点作者 ementally大约 1 年前

6 条评论

ahmedfromtunis大约 1 年前
That&#x27;s not what bothers me.<p>My problem with Flatpak is how huge are the downloads, especially when on a metered connection.<p>Last month I installed Kdenlive, and the size of the downloaded files was around 3 gb, to which the app itself contributed around 40 mb. (I use Ubuntu.)<p>A week later, I wanted to install another app (I forgot which one), but again, it was 3 gb download for 30ish mb app.<p>And then this week I ran `Flatpak update`, and it needed yet another 3 gb to download just because there was a new Kdenlive version (again, around 40 mb)!<p>How on earth does it make sense to have to download 10 gb worth of data just for apps that only total 100 mb?
评论 #39841162 未加载
评论 #39841222 未加载
评论 #39841225 未加载
评论 #39841234 未加载
ibotty大约 1 年前
(2022), and the article was not 100% correct even then.
评论 #39840485 未加载
planede大约 1 年前
It feels like the update at the top entirely invalidates the article. At least I don&#x27;t see why pinning dependency versions at the source level would be necessary for reproducible builds.
Joel_Mckay大约 1 年前
On the one hand it has all the disadvantages of static linking, and on the other hand it has all the disadvantages of out-of-band package managers.<p>They are unfortunately a necessary evil for keeping LTS OS running.
评论 #39840549 未加载
ementally大约 1 年前
Related: &quot;Flathub is insecure for distributing cryptocurrency software&quot;.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;feather-wallet&#x2F;feather&#x2F;issues&#x2F;47">https:&#x2F;&#x2F;github.com&#x2F;feather-wallet&#x2F;feather&#x2F;issues&#x2F;47</a>
ementally大约 1 年前
Guix seems the best when it comes to reproducibility <a href="https:&#x2F;&#x2F;guix.gnu.org&#x2F;en&#x2F;blog&#x2F;2024&#x2F;identifying-software&#x2F;" rel="nofollow">https:&#x2F;&#x2F;guix.gnu.org&#x2F;en&#x2F;blog&#x2F;2024&#x2F;identifying-software&#x2F;</a>