/srv/irclogs.ubuntu.com/2021/12/29/#snappy.txt

dob1it's not clear to who verify snap packages, because for ubuntu deb ones there is the debian/ubuntu teams, but for snap ones?  everyone can submit a snap package to snap store?09:41
dob1*clear to me09:41
dob1it's a trusted souce like the deb packages ?09:43
dob1*source09:43
ogra_dob1, snaps are generally fully confined and can not access anythig on the host without using pre-defined snap interfaces ... on upload there are automatic checks which interfaces a snap defines...12:22
dob1ogra_, my question was different12:22
ogra_dob1, while non-dangerous interfaces are typically allowed (desktop apps being able to output on display etc), any of the dangerous interfaces trigger a manual review of the security team12:23
dob1ogra_, that is an ubuntu teams ?12:24
ogra_so there *is* the same level (i'd say even a higher one) of review a deb gets (for a deb reviews only happen on first upload, later revisions are based on the trust towards the uploader) 12:24
ogra_for snaps each single upload is auto-checked ... if a snap changes its security policies, that upload will trigger a new review 12:25
ogra_it is the reviewers team on the forum (see topic) ... and all reviews are publically discussed before an exception is granted ... (see the "store-request" category on the forum)12:26
dob1ogra_, thanks for the info12:37

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!