danhab99@programming.dev to linuxmemes@lemmy.world · 18 hours agonixpkgs > aurprogramming.devimagemessage-square33fedilinkarrow-up1233arrow-down122file-text
arrow-up1211arrow-down1imagenixpkgs > aurprogramming.devdanhab99@programming.dev to linuxmemes@lemmy.world · 18 hours agomessage-square33fedilinkfile-text
minus-squarekevincox@lemmy.mllinkfedilinkarrow-up4·11 hours agoYes, on one hand every commit to nixpkgs needs review (to some degree) on the other hand there are far too many committers to nixpkgs. There are also gaps such as the bots to auto-merge packages with maintainer approval, so a simple attack looks like this: Submit a package with you as a maintainer. Create a new GitHub account and send a malicious update to that package. Use a bot to merge with maintainer approval. So nixpkgs is better than the AUR, but it isn’t great and unlike Arch has no separate official repos.
Yes, on one hand every commit to nixpkgs needs review (to some degree) on the other hand there are far too many committers to nixpkgs.
There are also gaps such as the bots to auto-merge packages with maintainer approval, so a simple attack looks like this:
So nixpkgs is better than the AUR, but it isn’t great and unlike Arch has no separate official repos.