Hacker News new | ask | show | jobs
by this_user 3 days ago
No, it's not. If Debian had a community-maintained repo of additional packages, the same thing could happen there.

The fundamental problem is having something that has very loose oversight and next to no controls. That may have worked in the past, but in the day and age of constant supply chain attacks, it's a major liability.

2 comments

Community-maintained repo is again a choice/option, how does that changes from LTS to Rolling release ?
GP was talking about why Arch isn't used in enterprise, not what happened in the post.