|
|
|
|
|
by goodpoint
1755 days ago
|
|
Debian is not only doing both peer review of the packages but it's reviewed by the users. Also, packages are rebuilt from source centrally. And finally, there is a number of large companies that provide legal indemnification, long term support and so on as part of large contracts. I.e. a 20-years long contract to provide all the software for an airport, or all branches of a bank, or a family of medical devices or cruise ships. Those companies review the distro very carefully. |
|
Second, if these companies are in fact auditing the code (which is a lot of code!), as opposed to just selling insurance and hoping for the best, that means that
a) it's some employee's job to spend a portion of their time reviewing the code
b) when they find issues, they report those bugs somewhere, so that the bug gets fixed
Can you point to either a job posting that lists reviewing Debian packages as part of the job requirements (or equivalently, someone's résumé/LinkedIn that says they did this work), or a bug report from one of these auditors?