Hacker News new | ask | show | jobs
by symtos 3677 days ago
there was a paper published 2008 on the state of linux/bsd package managers. some of the information is outdated (eg. pacman now signs their packages) however it is probably still of interest, esp. with all the language-specific package managers bent on repeating the security fuckups of the 90s/00s

https://isis.poly.edu/~jcappos/papers/cappos_mirror_ccs_08.p...