3 ms·
I believe that this kind of issue is possible with most language specific package repositories. That combined with the fact that a lot of developers upgrade dep
by rvdginste 5y ago
I believe that this kind of issue is possible with most language specific package repositories. That combined with the fact that a lot of developers upgrade dependencies without giving it a lot of thought (newer is better) probably means that this will happen again.
Still, when I update packages on my Debian install, I am not worried at all about this kind of issue. That makes me wonder if and why Debian packages would be safer. I think that the following are reasons that I trust official Debian packages:
* it is a curated list of software: confidence in the quality of the software
* maintainers follow up on security issues: confidence in security issues being fixed in a timely manner
* packages are signed: confidence that package is created by a trusted maintainer
* trustworthy maintainers: not everyone can upload new versions of packages, it takes time to become a new maintainer
So it makes me wonder whether a similar concept of curated repositories for language specific package repositories would be useful or needed... am I the only one to think about this?