Lock down flatpak software management

This commit is contained in:
Aaron Rainbolt 2025-10-31 15:23:12 -05:00
parent 948c96afe9
commit 8b766fc3ad
No known key found for this signature in database
GPG key ID: A709160D73C79109
4 changed files with 966 additions and 0 deletions

6
debian/security-misc-shared.hide vendored Normal file
View file

@ -0,0 +1,6 @@
## Copyright (C) 2025 - 2025 ENCRYPTED SUPPORT LLC <adrelanos@whonix.org>
## See the file COPYING for copying conditions.
## Allows users in the 'sudo' group to install Flatpak software without
## authorization. Breaks user/sysmaint separation, thus disabled.
/usr/share/polkit-1/rules.d/org.freedesktop.Flatpak.rules