4 ms·
> I think Drew makes a good point about the fact that distributions implicitly perform a 'review' step for packages, but I'm not certain I agree with the idea
by nickitolas 4y ago
> I think Drew makes a good point about the fact that distributions implicitly perform a 'review' step for packages, but I'm not certain I agree with the idea that leaving all packaging to distributions is the best approach overall.
As was mentioned in this reddit comment on this very topic (https://www.reddit.com/r/linux/comments/uohnzg/when_will_we_learn_drew_devault_of_rusts_and/i8fl5e0/?utm_source=reddit&utm_medium=web2x&context=3 https://www.reddit.com/r/linux/comments/uohnzg/when_will_we_...) package managers usually do not have a review process for updates:
> System package managers do not have a review process for package updates. Not for all packages, at least, and I would argue not for many packages.
> (...)
> The job of a package maintainer is to package software, not to perform security audits. They probably even lack the skills for performing security audits, because they are package maintainers, not security experts.
Now, you could make an argument that any filter, if not necessarily an audit or review cycle, just some time delay and having to convince a person that it's worth adding, is enough to add some measure of security. But equating it with "review" is just a misrepresentation of reality. And keep in mind that (To my understanding) distributions handle a vastly smaller set of packages than the tools Drew is proposing they replace. And I often hear about how they struggle to keep up with that. I doubt he doesn't know all this, so it's hard to read this as anything other than a bad faith argument to bash on things he doesn't like.