4 ms·
Yep, I'm aware of that. Although not every Linux distribution makes that distinction and the person to whom I replied certainly didn't leave room for that. Bu
by binarycrusader 14y ago
Yep, I'm aware of that. Although not every Linux distribution makes that distinction and the person to whom I replied certainly didn't leave room for that.
But in the past, even the packages in the "first tier" were often pretty busted. But even for that tier, Linux distributions are not performing "extensive vetting and rigorous testing". They don't generally test beyond relying that other components that use it work as expected, and for many components, those are only as well tested as the tests that are included with the component.
Yes, some distributions do run security analysis tools or other things on the components they integrate, but that still doesn't count as "extensive vetting and rigorous testing".