704
you are viewing a single comment's thread
view the rest of the comments
[-] Rustmilian@lemmy.world 43 points 7 months ago

Just use trusted repos 👍
We have GPG for a reason.

[-] AlexWIWA@lemmy.ml 13 points 7 months ago

There are a lot more ways to sneak malware into a system. Especially if some apps aren't being maintained anymore. Linux is definitely safer, but you shouldn't let your guard down

[-] rockrelishpiealamode@lemmy.ml 7 points 7 months ago

especially if you're a developer. There are a lot of shenanigans going on with malware npm packages that prey on easy typos. I imagine it's the same with other library installers for other languages too

[-] AlexWIWA@lemmy.ml 3 points 7 months ago

Funny you bring this up because it's exactly what I was thinking of. A million small packages and dependencies and who knows if the repos got hijacked

[-] AceFuzzLord@lemm.ee 3 points 7 months ago

Okay, what happens if your repo doesn't have a specific software you are looking for? A trusted repo is good, but it won't have everything you might want. This is especially true for new software or less popular software.

[-] Rustmilian@lemmy.world 6 points 7 months ago* (last edited 7 months ago)

Install nix, flatpack, etc. ◉⁠‿⁠◉

[-] caseyweederman@lemmy.ca 2 points 7 months ago

You audit the code

this post was submitted on 19 Nov 2023
704 points (90.6% liked)

linuxmemes

19747 readers
1820 users here now

I use Arch btw


Sister communities:

Community rules

  1. Follow the site-wide rules and code of conduct
  2. Be civil
  3. Post Linux-related content
  4. No recent reposts

Please report posts and comments that break these rules!

founded 1 year ago
MODERATORS