Flatpak

Flatpak 121,050 (github.com/flatpak/flatpak (https://github.com/flatpak/flatpak 5,076 ), LGPL-2.1) targets desktop apps on any distribution and is decentralized: anyone can host a remote, though Flathub 10,968 (3,472 apps listed from this host) is the one everyone uses. Apps build on shared runtimes (Freedesktop, GNOME, KDE) stored with OSTree, which deduplicates files between versions much as pnpm 69,400 's store does, and run in a bubblewrap sandbox, which works in WSL2 6 . Install kibi, a 2.1 MB terminal text editor.

Installing a small Flatpak app and tightening its sandboxShell
flatpak remote-add --user --if-not-exists flathub \
  https://dl.flathub.org/repo/flathub.flatpakrepo
flatpak install --user --noninteractive flathub com.github.ilai_deutel.kibi >/dev/null
flatpak list --user --columns=application,branch,size
flatpak info --show-permissions com.github.ilai_deutel.kibi
flatpak override --user --nofilesystem=host com.github.ilai_deutel.kibi
flatpak run --command=sh com.github.ilai_deutel.kibi \
  -c 'ls ~ | wc -l; cat /etc/os-release | head -1'
Output
com.github.ilai_deutel.kibi     stable  2.1 MB
org.freedesktop.Platform        25.08   668.9 MB
org.freedesktop.Platform.GL.default     25.08   462.4 MB
org.freedesktop.Platform.GL.default     25.08-extra     462.4 MB
org.freedesktop.Platform.codecs-extra   25.08-extra     43.4 MB
[Context]
filesystems=/var/tmp;/tmp;host;
0
NAME="Freedesktop SDK"

The 2.1 MB app pulled in 1.6 GB of runtimes (two minutes here), which later apps reuse. kibi asks for filesystems=host, as an editor must; after the override your home folder looks empty inside the sandbox, and /usr is the Freedesktop runtime, not Ubuntu 225 . flatpak override --user --reset undoes it.