4 ms·
> This seems like further evidence that distro package managers aren't the way forward On the contrary, distributions are here to stay and they are growing the
by ex_amazon_sde 5y ago
> This seems like further evidence that distro package managers aren't the way forward
On the contrary, distributions are here to stay and they are growing their adoption on many platforms including hi-end "IoT" and cars.
No sensible organization runs bleeding edge OSes on their airplanes, power plants, payment processors, industrial plants and so on...
This also applies to not pulling random packages from random github repos using some language-specific package manager hoping they don't contain backdoors.
Case in point: the CIP project https://www.cip-project.org/ https://www.cip-project.org/ aims to backport security fixes to Linux for 25 years after each CIP-approved release. This is because people expect to run the same kernel/OS for 30+ years.
- throwaway894345 5y ago> On the contrary, distributions are here to stay Seems like you misunderstood me. I said distro package managers, not distros. You even quoted me... > No sensible organization runs bleeding edge OSes on their airplanes, power plants, payment processors, industrial plants and so on... Most organizations don't run all of those things, and you don't need a bleeding edge distro to install up-to-date software. > This also applies to not pulling random packages from random github repos using some language-specific package manager hoping they don't contain backdoors. The obvious false dichotomy being that you either have to pull ancient software from a distro package repo or you depend on random packages. As though it's impossible to install vetted software with a language package manager. > This is because people expect to run the same kernel/OS for 30+ years. Right, but we're not talking about kernels, we're talking about the packages in repos.
- sk1459 5y agoI would not consider the contents of crates.io to be “vetted software”. If the burden is on the developer to carefully evaluate literally hundreds of dependencies, which may each be written in their own package-specific micro language of macros and present in several versions, then I think that’s a pretty substantial cost to bear. More likely, that expensive, unglamorous work will be papered over and ignored.
- bluGill 5y ago25 years is nothing. Auto parts dealers stock parts for cars that are more than 40 years old. Not even special order, the parts are on the shelf. Kernels should have support lifetimes of hundreds of years. (not every one, but some of them)