3 ms·
Your question feels insane to me for production environments. Why aren't you doing a version cutoff of your packages and either pulling them from some network/l
by chaps 6mo ago
Your question feels insane to me for production environments. Why aren't you doing a version cutoff of your packages and either pulling them from some network/local cache or baking them into your images?
- arandomhuman 6mo agoAforementioned security vulnerabilities don’t strike as a potential reason to you?
- chaps 6mo agoFriend, considering the supply chain attacks going on these days, automatically updating everything, immediately, probably isn't the perfect move either.
- askl 6mo agoIgnoring the real benefits of security updates to prevent the unlikely event of supply chain attacks sounds like a weird tradeoff.
- chaps 6mo agoA weird tradeoff but an increasingly important tradeoff to keep in mind nonetheless. Like I said, updating immediately isn't a perfect answer. But neither is waiting. I hope you're having this discussion, at least.
- bluGill 6mo agoYou need to automatically update from a trusted source. That source better audit and update constantly. Which is hard.
- LtWorf 6mo agoStable distributions have security teams.
- pavon 6mo agoThat local cache is often implemented as a drop-in replacement for the upstream package repository, and packages are still installed with the same package manager (yum,apt,pip,npm).
- chaps 6mo agoNo, this is not always the case. Regulated industries pin their package versions and store those versions for pulling.
- AntiUSAbah 6mo agoI don't just run a java spring boot application. I run other things on my production system. It doesn't matter much were i pull them from though, i only do this with packages which have plenty of dependencies and i don't want to assemble my own minimal image.