4 ms·
Could not agree more, although I dislike Arch. The reason I do is since it's extremely unsafe, I would want something as bleeding edge as Arch but with a purely
by klrr 13y ago
Could not agree more, although I dislike Arch. The reason I do is since it's extremely unsafe, I would want something as bleeding edge as Arch but with a purely functional package manager like Nix or GNU Guix. (I know you can install Nix on Arch but then I will still have to use Nixpkg repo.)
- w1ntermute 13y agoWhat do you mean by unsafe? It seems stable enough for a laptop. I wouldn't run it on a production server though.
- yogo 13y agoWhy not? Because of the problems due to running updated software or are you aware of some problem with packages? I ask because I have run Arch in production for the past 3 years on about 10 servers without any problems (knock on wood). Only official packages and always after quickly testing the latest pacman -Syu on a test machine. Compare to a couple Ubuntu servers I have to deal with I have to go out of the way to get more recent packages, which are often unofficial (I avoid having to build packages where possible).
- mintplant 13y agoMany AUR packages just pull from the HEAD of some git repo or pull down X random tarball from a URL. With something like Debian, you have layers of package maintainers in the middle to insulate against attacks, and specific, immutable bundles of data included in the packages themselves. Also, the entire Debian infrastructure (signing keys and all) being compromised, and such an incident going unnoticed, is a much less likely occurrence than the same for the hosting site some individual software author uses. Sure, you can still add third-party repositories to Debian and install deb packages from outside the main sources. But when you do that, you're making a conscious decision to do so, on a package-by-package basis. Any package you pull from AUR could be vulnerable, unless you manually check the source of each and every one. When you install from the Debian repos, you can trust that a certain standard of quality and security is being upheld.
- w1ntermute 13y agoHow does this compare to the safety of Ubuntu? Is a rolling release distro inherently less safe than a fixed release distro?
- klrr 13y agoIf I run bleeding-edge packages I want atomic updates (if install fail it won't change the state of the rest of the system) and support for roll-back (if a package is unstable I can easily go back one version without ruining the dependency tree for all other packages).