The conversation landed on a blunt point: Flatpak already solves real deployment problems, but its current security story is badly constrained by compatibility with old Linux apps and old distro releases. People who package apps for
Flathub described how this plays out in the weeds. Newer, narrower permissions exist, but they can be unusable for years because old Flatpak versions on long-supported distros cannot understand them. That forces maintainers to request much broader permissions like full device access, which then makes apps look unsafe even when the real need is narrow, such as game controller support.
That backward-compatibility trap shaped most of the technical criticism. Flatpak’s model works best when apps are written for portals and system file pickers from the start. Many desktop apps are not. To keep them working, maintainers punch holes in the sandbox, often granting home-directory or host filesystem access up front. Several comments argued that this is the central compromise in Flatpak’s design, not a minor bug. It gives Linux a path toward sandboxed desktop apps, but only by carrying legacy behavior that weakens the default guarantee and confuses users who expect mobile-style permissions.
The strongest defense of the grant was strategic rather than ideological. Flatpak was framed as infrastructure for government and enterprise Linux rollouts, especially on immutable or centrally managed desktops. Even skeptics who doubted Flatpak itself would be the long-term winner said the underlying work on portals,
Wayland and
PipeWire integration, and desktop security contexts has value beyond one package format. The opposite camp said that is exactly the problem: Flatpak has become too tightly coupled to package management, portals, and Linux desktop internals, so public money is being spent on a messy stack instead of cleaner foundations.
A second thread focused on the Sovereign Tech Agency itself. Some wanted permanent structural funding for critical open source projects rather than repeated grants. Others argued the agency is doing the right job for its size, funding the “get it adoption-ready” phase and leaving long-term support to procurement and support contracts once governments actually deploy the software. That view resonated more than the call for the agency to directly employ developers. People familiar with Germany’s public-sector pay scales and legal constraints said direct state hiring would be a bureaucratic trap and would not reliably attract senior engineering talent.
The mood was supportive of public funding for open source in general, but much less trusting of Flatpak as the vehicle. Even people who like Flatpak described it as useful, leaky, and unfinished. The grant was seen as reasonable if it buys better granular permissions, better portal adoption, and fewer blanket exceptions. It was seen as misallocated if it mostly entrenches a packaging system that still gets security by asking users and maintainers to work around legacy desktop assumptions.