It is now simple to build and run a desktop application inside a sandbox, using systems such as flatpak, to isolate it from the rest of the system. This talk will discuss current advances in sandboxing for desktop applications, including an overview of how the sandbox is created, the restrictions it imposes, and the technologies used to make existence in a sandbox seamless (including portals and services such as PipeWire).
