this post was submitted on 15 Feb 2025
186 points (98.4% liked)

Linux

7242 readers
528 users here now

A community for everything relating to the GNU/Linux operating system

Also check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] MissingInteger@lemm.ee 6 points 2 months ago (1 children)

So you linked to apt.
I guess good for anyone who finds this interesting…
But more on topic here is is a link to answer from 2020 from an flatpak maintainer:

If a user installs or updates a specific app-id the code verifies that:

  • The new app is gpg signed by a trusted key
  • Checksum verifying that all files are untampered with
  • The new app has that app id
  • The new app has a later timestamp on update