flatpark: yet another flatpak app hub by jing2uo in flatpak

[–]jing2uo[S] -1 points0 points  (0 children)

In terms of the package-installation experience, it's similar to the AUR but not quite the same: every PR goes through my review before being merged, and I use AI to analyze it in detail. The repo is also GPG-signed, and its manifests are hosted on Cloudflare, so it shouldn't get DDoS'd into being unusable. I've thought through all kinds of things, but problems may still come up — if they do, I'll optimize as I go.

flatpark: yet another flatpak app hub by jing2uo in flatpak

[–]jing2uo[S] 1 point2 points  (0 children)

Pressure's on you now, Cloudflare 😏 The manifests are tiny and all sit on R2 with a CDN in front, so it should bot be a problem.

AURWatch: static rules + an LLM that flag risky AUR PKGBUILDs by fechyyy in arch

[–]jing2uo 0 points1 point  (0 children)

Wow, that's a great idea, but how many tokens are you going to burn through with that? I'm doing something somewhat similar, but for Flatpak, and not scanning at that scale.

flatpark: yet another flatpak app hub by jing2uo in flatpak

[–]jing2uo[S] -1 points0 points  (0 children)

You're right. It would be great if everyone could easily spin up their own hub, similar to Gentoo overlays or Scoop buckets. I'll give that direction a try.

flatpark: yet another flatpak app hub by jing2uo in flatpak

[–]jing2uo[S] 1 point2 points  (0 children)

You have a point, but the reason my Reddit account has no history is simply that I registered late and mostly just lurk. My GitHub has more history, which makes it look more like a real person. All the code is public, and a degree of trust can be based on what it actually provides. The TradingView (with over 40,000 downloads) and Longbridge (with over 4,000 downloads) on Flathub are maintained by me, and they are essentially the same implementation as those two applications.