3 ms·
> Why can't we just static link everything, and distribute binaries Because what happens if there's vulnerability in say zlib or openssl. As a distributor you'
by throw_a_grenade 4y ago
> Why can't we just static link everything, and distribute binaries
Because what happens if there's vulnerability in say zlib or openssl. As a distributor you'd need to rebuild everything (volunteer-run distros don't have sufficient cpu time to rebuild the whole archive at once), and in the process check if the update won't break anything in each and every package. Or rely on upstream (which may be unresponsive, because they're also volunteers).
This might be manageable in relatively small, single-language, corporate-backed apps, but is not viable in volunteer-run operating systems with ~50k packages written in every single programming language invented.
No one distro will risk this (imagine Phoronix article: "After 1 year, CVE-2023-123456 fixed in only 30% of packages in StaticLinux!").
I mean, you're free to try. I'll provide time-to-fixed statistics for all your CVEs.