Flatpak

ID

flatpak

Links

Home page · Documentation · Repository · Wikipedia

Upstream stars

⭐ 5,078

Last commit

2026-09-28

Version requirement

>= 1.9.1

Cooldown

✓

Platforms

🅱️ BSD · 🐧 Linux · ⨂ Unix

Operations

installed · outdated · search · install · upgrade · upgrade_all · remove · cleanup · doctor

purl types

pkg:flatpak/

CLI name

flatpak

Issues and PRs

📦 manager: flatpak

Source

flatpak.py

Flatpak manages sandboxed desktop applications pulled from remotes like Flathub.

mpm covers applications only: every listing passes --app, so runtimes and SDKs stay out of scope.

Note

All operations target the system-wide scope except cleanup which only repairs the user installation. Per-scope targeting (system vs user) is tracked in #1725.

Note

Escalation is polkit’s job, so no operation is marked sudo: flatpak hands system-scope mutations to its privileged system helper over D-Bus, which authorizes them through polkit (Flathub documents plain flatpak install). Under a strict polkit policy, unattended mutations need a rule permitting them without interactive authentication.

What mpm adds to flatpak

Through mpm, flatpak gains --exact and --extended search, to narrow to exact names or match descriptions.

Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover flatpak alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.

Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.

Your flatpak commands, in mpm

You already know flatpak: each operation maps one-to-one onto mpm, in an interface shared by every manager.

To…

With flatpak

With mpm

List what’s installed

flatpak list --app --columns=name,application,version > --ostree-verbose

mpm --flatpak installed

List outdated packages

flatpak remote-ls --app --updates --columns=name,application,version --ostree-verbose

mpm --flatpak outdated

Search for a package

flatpak search gitg --ostree-verbose

mpm --flatpak search gitg

Install a package

flatpak install --noninteractive org.gnome.Dictionary

mpm install pkg:flatpak/org.gnome.Dictionary

Upgrade one package

flatpak update --noninteractive org.gnome.Dictionary

mpm --flatpak upgrade org.gnome.Dictionary

Upgrade everything

flatpak update --noninteractive

mpm --flatpak upgrade --all

Remove a package

flatpak uninstall --noninteractive org.gnome.Dictionary

mpm remove pkg:flatpak/org.gnome.Dictionary

Run health checks

flatpak repair --user --dry-run

mpm --flatpak doctor

Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.

Operations

Operation

Supported

Notes

installed

✅

outdated

✅

Each pending update costs one follow-up flatpak info call to recover its installed version.

orphans

search

✅

Exact and extended search backfilled by mpm.

install

✅

A package already installed as a dependency is marked explicit by mpm.

upgrade

✅

upgrade_all

✅

remove

✅

sync

cleanup

✅

The --orphans flag runs the system-wide orphan sweep.

doctor

✅

Configuration

  • Ignore flatpak on the mpm CLI by passing the --no-flatpak option.

  • Ignore it for every run in your configuration:

    [mpm]
    flatpak = false
    
  • Raise the timeout of all flatpak calls:

    [mpm.overrides.flatpak]
    timeout = 900
    
  • Run mpm config-template flatpak to print all overridable settings for your configuration file:

    [mpm.overrides.flatpak]
    cli_names = [
        "flatpak",
    ]
    cli_search_path = []
    dry_run = false
    ignore_auto_updates = true
    plan = false
    post_args = []
    pre_args = []
    pre_cmds = []
    requirement = ">=1.9.1"
    stop_on_error = false
    unmaintained = false
    version_cli_options = [
        "--version",
    ]
    version_regexes = [
        "Flatpak\\s+(?P<version>\\S+)",
    ]
    

Recipes

A few jobs you would otherwise script around flatpak, one mpm command each:

  • Snapshot and clone a machine: mpm --flatpak dump flatpak.toml, then mpm restore flatpak.toml on the next one.

  • Export a Brewfile entry instead: mpm --flatpak dump --brewfile Brewfile.

  • Export a compliance SBOM: mpm --flatpak sbom (CycloneDX by default, --spdx for SPDX).

  • Gate CI on health: mpm --flatpak doctor relays Flatpak’s own diagnosis and exits non-zero on trouble.

Privilege escalation

mpm runs this manager as the current user and never prepends sudo by default. Flip the policy for its privileged operations with --sudo or the per-manager sudo override.

None of its operations is privileged.

See privilege escalation for the full policy.

Cooldown

mpm enforces its release-age cooldown on Flatpak with its own per-package probe: before an install or upgrade, it reads the publication date of the package’s latest release and holds back any release younger than the window (mpm --cooldown 7 --flatpak upgrade --all skips anything published in the last 7 days): a guard against a compromised or yanked fresh release landing before anyone notices.

  • Status: ✅ Enforced (mpm per-app probe)

  • Mechanism: ostree commit date read by flatpak remote-info, each too-fresh app held back

  • Reference: flatpak remote-info

A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:

  • Registry: Flathub

  • Retraction: Relabel: end-of-life metadata delists the application, and the maintainer documentation describes no way to remove or roll back an individual build (maintenance)

  • Publish date: ✅ ostree commit timestamp, stamped by the build service and read by flatpak remote-info: the clock of mpm’s per-app probe

Reference traces

A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know Flatpak well and a transcript below looks wrong, or a newer release changed its output format, report it.

$ flatpak list --app --columns=name,application,version         > --ostree-verbose
Peek	com.uploadedlobster.peek	1.3.1
Fragments	de.haeckerfelix.Fragments	1.4
GNOME MPV	io.github.GnomeMpv	0.16
Syncthing GTK	me.kozec.syncthingtk	v0.9.4.3
Builder	org.flatpak.Builder
$ flatpak remote-ls --app --updates --columns=name,application,version             --ostree-verbose
GNOME Dictionary	org.gnome.Dictionary	3.26.0
Files	org.gnome.Nautilus	42.2

Version check

The version is probed by running:

$ flatpak --version
Flatpak 1.16.1

and extracted with:

r"Flatpak\s+(?P<version>\S+)"

Upstream project

Metrics

flatpak/flatpak

Activity

commit activity commits since open issues open pull requests

Popularity

forks watchers contributors

Metadata

latest release release date license main language

Changelog

  • 8.0.0 (2026-09-20)

    • Gate flatpak under --cooldown with a per-app probe reading the publication date of each app’s latest build from its remote, holding back any release younger than the window.

    • Pin a runtime already installed as a dependency when mpm install or mpm restore names it, so mpm cleanup --orphans keeps it. This raises the flatpak floor to 1.9.1.

    • Fix search reporting only its first result and silently dropping every other match.

    • Fix the search output shown on its page, whose tab separators had been flattened to spaces, leaving a transcript its own parser could not read.

  • 6.4.0 (2026-04-27)

    • Add remove operation. Closes #1775.

  • 5.19.0 (2024-11-14)

    • Fix parsing of descriptions with spaces.

  • 5.6.0 (2022-09-26)

    • A package whose version cannot be parsed now reports no version, instead of the literal string unknown.

  • 3.2.0 (2020-05-31)

    • Fix search keying its results on the package name instead of the application ID: the two columns were swapped when unpacking a result row.