3 ms·
> Besides that, packages in nixpkgs often have known vulnerabilities for months I would be cautious not to assume the alternatives are perfect https://security
by ris 4y ago
> Besides that, packages in nixpkgs often have known vulnerabilities for months
I would be cautious not to assume the alternatives are perfect https://security-tracker.debian.org/tracker/status/release/stable https://security-tracker.debian.org/tracker/status/release/s.... It's not uncommon for nixpkgs to get a security fix out before debian.
I think the real issue is that nixpkgs has a lot more "long tail" packages than most package managers, where security issues are grey areas. e.g. upstream aren't great at handling them, making new releases with the fix or god forbid acknowledging the need to be able to backport a fix to a stable branch.
Though I don't disagree that timely reviews would help an awful lot in nixpkgs.