2 ms·
it is true, debian particularly has very good track record: https://security.stackexchange.com/questions/243455/was-there-ever-any-malware-found-in-debian-ubun
by throwaway71271 3y ago
it is true, debian particularly has very good track record:
https://security.stackexchange.com/questions/243455/was-there-ever-any-malware-found-in-debian-ubuntu-packages https://security.stackexchange.com/questions/243455/was-ther...
however, cpan, npm, ports, homebrew, gems etc there are examples: https://docs.brew.sh/Acceptable-Casks#apps-that-bundle-malware https://docs.brew.sh/Acceptable-Casks#apps-that-bundle-malwa...
but i was hinting more at the: there are so many packages, and so many that are used rarely, that there is no way we know.
i think just running weekly modified files report and running things in sandboxes also dont give internet to all apps is good enough for me, and of course be critical of the sources you install from, reputable repos are better than non reputable ones, but are not immune.