danhab99@programming.dev to linuxmemes@lemmy.world · 1 day agonixpkgs > aurprogramming.devimagemessage-square33fedilinkarrow-up1251arrow-down125file-textcross-posted to: linux_memes@programming.dev
arrow-up1226arrow-down1imagenixpkgs > aurprogramming.devdanhab99@programming.dev to linuxmemes@lemmy.world · 1 day agomessage-square33fedilinkfile-textcross-posted to: linux_memes@programming.dev
minus-squarekevincox@lemmy.mllinkfedilinkarrow-up6·23 hours agoYes, on one hand every commit to nixpkgs needs review (to some degree) on the other hand there are far too many committers to nixpkgs. There are also gaps such as the bots to auto-merge packages with maintainer approval, so a simple attack looks like this: Submit a package with you as a maintainer. Create a new GitHub account and send a malicious update to that package. Use a bot to merge with maintainer approval. So nixpkgs is better than the AUR, but it isn’t great and unlike Arch has no separate official repos.
Yes, on one hand every commit to nixpkgs needs review (to some degree) on the other hand there are far too many committers to nixpkgs.
There are also gaps such as the bots to auto-merge packages with maintainer approval, so a simple attack looks like this:
So nixpkgs is better than the AUR, but it isn’t great and unlike Arch has no separate official repos.