Enable a subset of Flathub by default #492

Open
opened 2025-11-18 17:46:00 +00:00 by catanzaro · 7 comments
Owner

In #463, which contains substantial previous discussion on this topic, I proposed the following changes to Fedora's use of Flathub:

  • Remove Flathub from the existing third-party software repositories feature (fedora-third-party) to resolve concerns about inadequate supply chain security (open source software not built from source).
  • Request, on behalf of Fedora Workstation, that Flathub either (a) remove open source software not built from source from the existing floss subset, or (b) expose a new subset featuring only open source software built from source. If Flathub agrees, Fedora Workstation would enable this subset by default in GNOME Software without requiring that the user enable third-party software sources. (Fedora would need to find developers willing to help Flathub implement this.)
  • Flathub would have lower priority than Fedora RPMs and Fedora Flatpaks in GNOME Software, to attempt to gain votes from developers who would otherwise be unwilling to support this proposal. This would still position Flathub to eventually become the primary source of apps for Fedora Workstation, because we would have very few Fedora Flatpaks in the Fedora Workstation Flatpak repo, and because Fedora RPMs will eventually disappear as part of the Fedora 2028 strategy ("Silverblue & Kinoite are ready to be our desktop Editions, with bootc" from Strategy 2028 update).
  • Optional: remove the existing third-party software sources feature and replace it with an enable proprietary software sources feature, which would expose the full Flathub. (This would require additional discussion in a separate ticket to agree on the details. Don't need to work it out here, since it is ancillary to the rest of this proposal.)

I'm splitting this proposal out from #463.

In #463, which contains substantial previous discussion on this topic, I proposed the following changes to Fedora's use of Flathub: * Remove Flathub from the existing third-party software repositories feature (fedora-third-party) to resolve concerns about inadequate supply chain security (open source software not built from source). * Request, on behalf of Fedora Workstation, that Flathub either (a) remove open source software not built from source from the existing floss subset, or (b) expose a new subset featuring only open source software built from source. If Flathub agrees, Fedora Workstation would enable this subset by default in GNOME Software without requiring that the user enable third-party software sources. (Fedora would need to find developers willing to help Flathub implement this.) * Flathub would have lower priority than Fedora RPMs and Fedora Flatpaks in GNOME Software, to attempt to gain votes from developers who would otherwise be unwilling to support this proposal. This would still position Flathub to eventually become the primary source of apps for Fedora Workstation, because we would have very few Fedora Flatpaks in the Fedora Workstation Flatpak repo, and because Fedora RPMs will eventually disappear as part of the Fedora 2028 strategy ("Silverblue & Kinoite are ready to be our desktop Editions, with bootc" from Strategy 2028 update). * Optional: remove the existing third-party software sources feature and replace it with an enable proprietary software sources feature, which would expose the full Flathub. (This would require additional discussion in a separate ticket to agree on the details. Don't need to work it out here, since it is ancillary to the rest of this proposal.) I'm splitting this proposal out from #463.
Owner

If Flathub agrees, Fedora Workstation would enable this subset by default in GNOME Software without requiring that the user enable third-party software sources. (Fedora would need to find developers willing to help Flathub implement this.)

This may trigger a broader re-discussion about enabling third-party FOSS repositories by default (particularly for an especially notable third party repository). I'm not sure this is something we want to cause.

> If Flathub agrees, Fedora Workstation would enable this subset by default in GNOME Software without requiring that the user enable third-party software sources. (Fedora would need to find developers willing to help Flathub implement this.) This may trigger a broader re-discussion about enabling third-party FOSS repositories by default (particularly for an especially notable third party repository). I'm not sure this is something we want to cause.
Author
Owner

I've edited the first comment here because I forgot to include the final point.

This may trigger a broader re-discussion about enabling third-party FOSS repositories by default (particularly for an especially notable third party repository). I'm not sure this is something we want to cause.

Where will our apps come from when RPMs are no longer an option? In #463 we just agreed that most Fedora Flatpaks will no longer be available by default. With Fedora 2028 goal, we lose RPMs. GNOME Software will feel pretty empty if we have no RPM software sources, only a few Fedora Flatpaks, and no Flathub.

I've edited the first comment here because I forgot to include the final point. > This may trigger a broader re-discussion about enabling third-party FOSS repositories by default (particularly for an especially notable third party repository). I'm not sure this is something we want to cause. Where will our apps come from when RPMs are no longer an option? In #463 we just agreed that most Fedora Flatpaks will no longer be available by default. With Fedora 2028 goal, we lose RPMs. GNOME Software will feel pretty empty if we have no RPM software sources, only a few Fedora Flatpaks, and no Flathub.
Owner

I'm aware, but the third-party repository policy isn't RPM specific. And there is no reason there wouldn't be other third-party Flatpak repositories in the future too.

I'm aware, but [the third-party repository policy](https://docs.fedoraproject.org/en-US/workstation-working-group/third-party-repos/) isn't RPM specific. And there is no reason there wouldn't be other third-party Flatpak repositories in the future too.
Author
Owner

Ah, I had forgotten about that policy. There is indeed no way to do this without revisiting many aspects of it. Some points:

The third-party nature of the repository must be apparent to the user when they enable it, as should the non-free status of its content, if such. To ensure this, repository files must initially include the enabled=0 (or equivalent) setting, and the user must explicitly enable third-party repositories to install from them. FESCo may grant an exception to waive this requirement.

We would need an explicit waiver to enable Flathub by default.

Just as with any software hosted by Fedora, third party repositories must not contain material that poses an undue legal risk for the Fedora Project or its sponsors. This risk includes, but is not limited to, software with known patent issues, copyright issues, or software tailored for conducting illegal activities. Fedora working groups should evaluate if a proposed addition or provider poses a significant risk, and if in doubt, confer with Fedora Legal for advice.

We would need to rewrite this requirement. Fedora Legal has concluded that we are not worried about enabling Flathub, but content present in Flathub clearly violates the requirements here.

Working groups and SIGs should maintain oversight over the software that is made available through third-party repositories, to prevent unvetted software being made available to Fedora users. As part of this, third-party repositories should allow easy auditing by Fedora Legal. This requirement implies that third-party repositories should limit themselves to a small number of packages, or that measures should be put in place to define which packages are made available from a particular repository by default.

This requirement would need to be removed.

Third-party repositories can supplement official Fedora software. In limited cases, they can be used to replace software included in the official Fedora repositories. Such situations require FESCo approval.

We would need to rewrite or remove this requirement too.

Ah, I had forgotten about that policy. There is indeed no way to do this without revisiting many aspects of it. Some points: > The third-party nature of the repository must be apparent to the user when they enable it, as should the non-free status of its content, if such. To ensure this, repository files must initially include the enabled=0 (or equivalent) setting, and the user must explicitly enable third-party repositories to install from them. FESCo may grant an exception to waive this requirement. We would need an explicit waiver to enable Flathub by default. > Just as with any software hosted by Fedora, third party repositories must not contain material that poses an undue legal risk for the Fedora Project or its sponsors. This risk includes, but is not limited to, software with known patent issues, copyright issues, or software tailored for conducting illegal activities. Fedora working groups should evaluate if a proposed addition or provider poses a significant risk, and if in doubt, confer with Fedora Legal for advice. We would need to rewrite this requirement. Fedora Legal has concluded that we are not worried about enabling Flathub, but content present in Flathub clearly violates the requirements here. > Working groups and SIGs should maintain oversight over the software that is made available through third-party repositories, to prevent unvetted software being made available to Fedora users. As part of this, third-party repositories should allow easy auditing by Fedora Legal. This requirement implies that third-party repositories should limit themselves to a small number of packages, or that measures should be put in place to define which packages are made available from a particular repository by default. This requirement would need to be removed. > Third-party repositories can supplement official Fedora software. In limited cases, they can be used to replace software included in the official Fedora repositories. Such situations require FESCo approval. We would need to rewrite or remove this requirement too.
Author
Owner

Metadata Update from @catanzaro:

  • Issue untagged with: meeting-request
  • Issue tagged with: meeting
**Metadata Update from @catanzaro**: - Issue **un**tagged with: meeting-request - Issue tagged with: meeting
Author
Owner

Today FESCo approved Flathub by default for atomic spins, but this change is NOT approved for RPM spins like Workstation. If Workstation Working Group decides to enable Flathub, we will still need to bring it to FESCo.

Today FESCo approved Flathub by default for atomic spins, but this change is NOT approved for RPM spins like Workstation. If Workstation Working Group decides to enable Flathub, we will still need to bring it to FESCo.
Author
Owner

We discussed this today, but nobody presented any strong opinions, and we did not agree to anything. Further discussion will be needed.

We discussed this today, but nobody presented any strong opinions, and we did not agree to anything. Further discussion will be needed.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
workstation/tickets#492
No description provided.