|
|
|
|
|
by morelisp
1458 days ago
|
|
Fedora currently packages 10646 crates. It's implausible that they're manually auditing each one at each upgrade for anything other than "test suites pass", let alone something like obfuscated security vulnerabilities. In the end most distros will be saved by the fact they don't upgrade quickly. Which is also accomplished by MVS without putting another attack vector in the pipeline. |
|
There's more than a hundred package maintainers (I'm not sure exactly how many), but the median is about 50 packages.
Do you think people can't keep up with the updates for 50 packages?