3 ms·
Sure, that gives you working binaries. But also security problems, because you don't control which versions of libraries you are using. Suddenly, all individual
by strictfp 7y ago
Sure, that gives you working binaries. But also security problems, because you don't control which versions of libraries you are using. Suddenly, all individual software packages must do their own security updates to keep the system secure. So the whole thing is a balance.
- blackhaz 7y agoYes. But if we can extract versions of libraries used to build packages then it would be easy to audit the system by cross-checking against CVEs. Those who prioritize security would remove the affected package(s) until a new version is available. My point here is to be able to install a new package when it's out, without disrupting the whole environment. For FreeBSD, for example, the new Firefox is already available. I have installed it, and it wouldn't run. I had to auto-update 300 MB of other stuff, including LibreOffice, PyCharm and even TeXLive, to get the system up to date for the new Firefox to be able to run.
- jrockway 7y agoYou do control what version of libraries you're using. You include the exact SHA256 of every dependency of every dependency, down to the toolchain itself. If you're saying "your distribution can't automatically update you if libc is vulnerable to something", that's true. More CPU time is required to react to major vulnerabilities, as everything has to be recompiled. However, it's not much CPU time, and the downsides of requiring more compute time are lower than the upsides of knowing exactly where your dependencies come from. And having your "getting started" instructions be "1) install bazel 2) bazel run //your:binary".