5 ms·
Not sure I understand your comment. Distribution package maintainers would ideally want to adhere to the same sets of standards as language ecosystem package ma
by SethMLarson 5y ago
Not sure I understand your comment. Distribution package maintainers would ideally want to adhere to the same sets of standards as language ecosystem package maintainers?
- rattlesnakedave 5y agoCorrect. We see less security issues w/ distro packages because they have better best practices, do more curation, and generally have more specialized xp doing this sort of thing. I remember an lwn article about Debian maintainers managing PGP keys a while back which was interesting- https://lwn.net/Articles/734767/ https://lwn.net/Articles/734767/
- goodpoint 5y agoDistributions like Debian are way more strict than that: - peer reviews including licensing review - package signing - various types of build and integration tests - reproducible builds - freeze periods - build hardening flags and sandboxing - strong identity verification with PGP web-of-trust
- mistrial9 5y agoI believe it is a combination of human social checks and math PGP, both .. that stand the test of time, since either one by itself can and will fail spectacularly, at exactly the wrong times
- aaaaaaaaata 5y agoWhich adds n days to their patch interval.
- Vogtinator 5y agoNot necessarily caused by those points, if at all a specific implementation.
- goodpoint 5y agoIf anything, it's the opposite. Distributions provide security patches that upstream often do not.