5 ms·
> If every package bundles libfoo what happens there's a security vulnerability in libfoo? That’s actually the key point that many people in this discussion se
by cbmuser 2y ago
> If every package bundles libfoo what happens there's a security vulnerability in libfoo?
That’s actually the key point that many people in this discussion seem to miss.
- pmontra 2y agoWhat happens is that libfoo gets fixed, possibly by the maintainers of the distro, and all the apps using it are good to go again. With multiple versions bundled to multiple apps, a good number of those apps will never be updated, at least not in a timely manner, and the computer will be left vulnerable.
- sunshowers 2y agoThen you get an alert that your libfoo has a vulnerability (GitHub does a pretty good job here!) and you roll out a new version with a patched libfoo.
- kelnos 2y agoAs a user, I don't want to assume that every single maintainer of every single app that uses (a statically linked) libfoo is keeping up to date with security issues in their dependencies and has the time and ability to promptly update their software. But I feel pretty safe believing that the debian libfoo package maintainer is on top of things and will quickly release an update to libfoo.so that all apps running on my system will be able to take advantage of.
- sunshowers 2y agoThat's fair, but the Debian maintainer could just as well update libfoo.a and kick off builds of all the reverse transitive dependencies of libfoo.a.
- tremon 2y agoSpecifically in the case of Debian, who is going to pay for all the additional infrastructure (build servers) that switching to dependency vendoring/static linking would require?
- sunshowers 2y agoGood question. I think someone would have to run the numbers here!