Listing Thumbnail

    Flox Container

     Info
    Sold by: Flox 
    Deployed on AWS
    Contains the Flox package manager, ready to use for demos, CI, or testing.

    Overview

    Play video

    Flox is a virtual environment and package manager all in one. With Flox you create development environments that put you into reproducible subshells with dependencies provided and configured for you. Even better, these environments layer so you can prepare different environments for different contexts and stack them when needing to work across contexts.

    Highlights

    • One-Command Project Setup
    • Your Tools, Everywhere
    • Environments With All the Comforts of HOME

    Details

    Sold by

    Delivery method

    Supported services

    Delivery option
    Container

    Latest version

    Operating system
    Linux

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Flox Container

     Info
    This product is available free of charge. Free subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Vendor refund policy

    Contact us

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Container

    Supported services: Learn more 
    • Amazon ECS
    • Amazon EKS
    • Amazon ECS Anywhere
    • Amazon EKS Anywhere
    Container image

    Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.

    Version release notes

    Hotfix for Nix vulnerability

    This is a hotfix release to patch a vulnerability in Nix. See https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj 

    For Linux installations of Flox, the vulnerability allows non-root users to gain root privileges by modifying sensitive files. macOS and container installations are not affected. This affects Flox installations >=1.3.2 up to this release.

    Full details from the Nix advisory

    A bug in the fix for CVE-2024-27297 allowed for arbitrary overwrites of files writable by the Nix process orchestrating the builds (typically the Nix daemon running as root in multi-user installations) by following symlinks during fixed-output derivation output registration. This affects sandboxed Linux builds - sandboxed macOS builds are unaffected. The location of the temporary output used for the output copy was located inside the build chroot. A symlink, pointing to an arbitrary location in the filesystem, could be created by the derivation builder at that path. During output registration, the Nix process (running in the host mount namespace) would follow that symlink and overwrite the destination with the derivation's output contents.

    In multi-user installations, this allows all users able to submit builds to the Nix daemon (allowed-users - defaulting to all users) to gain root privileges by modifying sensitive files.

    Details relevant to Flox

    Flox installations outside of containers default to a multi-user installation with allowed-users defaulting to all. Questions and additional info can be found in our community slack .

    Other fixes

    • Manifest parse errors now include line and column information, making it easier to locate syntax errors.

    Thank you to our community contributions this release

    • Manifest parse error improvements (@electricalen)

    Download Links

    [!NOTE] You can find the SHA256 checksums for Flox 1.11.2  and SHA512 checksums for Flox 1.11.2  online.

    Additional details

    Usage instructions

    Welcome to the Flox tool. Try out a few commands:

    • flox search fastfetch
    • flox install fastfetch
    • flox activate -- fastfetch
    • flox edit to make changes to the manifest.toml, add/remove packages and set hooks!

    See more comprehensive documentation and a tutorial at https://flox.dev/docs/ .

    Resources

    Vendor resources

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.