Snap 2,571 and Flatpak 121,050 ship whole applications to users; npm 2,036 , pip 21,050 and Cargo 6,602 assemble libraries into a program you are building. The design choices still echo the rest of this chapter.
| Snap | Flatpak | npm, pip, Cargo | |
|---|---|---|---|
| Unit | Application + base | Application + runtime | Library |
| Sharing | Base snaps | OSTree runtimes | Store or cache per user |
| Sandbox | AppArmor 454,622 , seccomp | bubblewrap, namespaces | None |
| Updates | Automatic, by channel | flatpak update | Only when you ask |
| Store | Snap Store (Canonical) | Any remote, mostly Flathub 10,968 | npmjs, PyPI 2,431 , crates.io |
The sandbox row matters most: a Flathub app cannot read your SSH keys unless its manifest asks, while a package installed by npm can run any code with your permissions (Supply-Chain Security). On servers and in CI, container images (Docker) do what these formats do on desktops.