3 ms·
How is that any different from PyPI, npm, cargo, etc?
by dezgeg 22d ago
How is that any different from PyPI, npm, cargo, etc?
- lrvick 21d agoThose are also all just as bad but you can at least run those fully in containers or vms and never let them touch your host system. Brew however is a system level package manager so it is expected to install your top level tools with substantial privilege, so for using it on a production capable system you would want maintainer signed commits, maintainer signed reviews, and 2+ maintainer signed reproducible builds, all with well known long lived keys controlled by smartcards of each maintainer on high trust systems. I am not just talking out of my ass here. We do all of the above in stagex because it is the bare minimum.
- angry_octet 21d agoThey are all significant risks, and we pay significant money to JFrog for their X-ray product to scan and alert on bad dependencies, and significant internal tooling to track which package was used on which developer enclaves.