4 ms·
> Maybe. The CI rules should be made public in that case, though, surely? Maybe they are? Agreed, but thankfully they are. The PRs link to <https://github.com/
by orra 3y ago
> Maybe. The CI rules should be made public in that case, though, surely? Maybe they are?
Agreed, but thankfully they are. The PRs link to <https://github.com/flathub/flatpak-external-data-checker https://github.com/flathub/flatpak-external-data-checker>. That said, it'd be clearer if the flathubbot 'user' profile also linked to that URL.
> The enormous amount of value the distros bring [...] is audit of packages (and packaging).
Yes, auditing against supply chain attacks is good! But there's also a risk in running outdated software. I don't have easy answers. But if automation leaves more time for the hard part, great.
- smallerfish 3y agoMaybe unfair to ask you (but thanks for the helpful answers so far). Is there a check for "this distribution comes from the official source"? Let's say some state actor compromises taaem's desktop computer, and changes the url in the manifest to (say) https://githսb.com/bitwarden/clients/releases/download/desktop-v2023.10.1/Bitwarden-2023.10.1-amd64.deb https://xn--githb-bjg.com/bitwarden/clients/releases/downloa... (that's a unicode lookalike ս in there, which in github at least renders without expansion as "github.com" - HN is smart enough to expand it), or something equally nefarious. CI's not going to catch that, right? And nobody's actually paying attention to changes?
- orra 3y agoNot an expert, but unfortunately I think you're right in identifying a potential attack vector with the Flathub maintainership model. Even if flathubbot is being used, manual changes can still be made by maintainers. And I think there are far more maintainers to trust, than for say scoop or winget. The difference is, Flathub has one repo per package (and hence allows more maintainers).