3 ms·
The repositories support signing so binaries that are sourced from these repositories are verified by the associated signatures during installation. If you trus
by rc00 3y ago
The repositories support signing so binaries that are sourced from these repositories are verified by the associated signatures during installation. If you trust the installation, would you include the execution in that same trust? Windows does not include signed repositories (or any that I know of) by default. (I could be wrong about that but if it does exist, the software collection is nowhere as vast as the distro repositories.)
1. Debian - SecureApt - https://wiki.debian.org/SecureApt https://wiki.debian.org/SecureApt
2. Arch - pacman/Package signing - https://wiki.archlinux.org/title/Pacman/Package_signing https://wiki.archlinux.org/title/Pacman/Package_signing
3. Fedora - RPM - Checking Package Signatures - https://docs.fedoraproject.org/en-US/fedora/latest/system-administrators-guide/RPM/#s1-check-rpm-sig https://docs.fedoraproject.org/en-US/fedora/latest/system-ad...
- nullindividual 3y agoWindows does not generally have the concept of a 'repository' (WinGet excluded, but that's fairly new). The Microsoft Store is the closest thing to a repo, and those are signed. Everything coming from Windows Update is also signed by a public CA.