3 ms·
The "balkanized" downstream has been working quite well, unlike malicious packages on PyPI. The only major issue was the OpenSSL fiasco that was due to overpat
by laykg 6y ago
The "balkanized" downstream has been working quite well, unlike malicious packages on PyPI.
The only major issue was the OpenSSL fiasco that was due to overpatching upstream. Overpatching indeed should stop but is not a flaw of the package manager itself.
- MaulingMonkey 6y ago> The "balkanized" downstream has been working quite well Disagreed. > The only major issue was the OpenSSL fiasco that was due to overpatching upstream There's a reason OpenSSL got forked as LibreSSL/BoringSSL - even downstream realized their approach wasn't cutting it, and they needed to go upstream and start burning everything down with fire. Granted, OpenSSL has been getting their act together - so perhaps unforking might be warranted? Meanwhile, the CVE database continues to be flooded with memory vulnerabilities. Distros dutifully push out the patches when they get them, but that's the bare minimum.