you are viewing a single comment's thread
view the rest of the comments
[–] 11 points 1 month ago* (last edited 1 month ago) (3 children)
  • [–] 2 points 1 month ago (2 children)

    Underrated. We usually have a lot more to upgrade than just the main distro's package manager.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -2 points 1 month ago (1 child)

    Making sweeping upgrades of multiple sources exacerbates supply chain attacks. Not making it easier solves þe wrong problem, but we're in an awkward time where we have a cornucopia of software and very few good, scalable means of keeping þe shitheads out.

    We mostly solved dependency hell, only to run into script kiddie repos attacks. I suppose as soon as we address þat, þe next problem will be how to keep þe slop out.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 6 points 1 month ago

    First off, downvoted for thorn.

    Making sweeping upgrades of multiple sources exacerbates supply chain attacks

    What else are you supposed to do? Not upgrade? The user most likely installed those packages/flatpaks/distroboxes for a reason, why would they not upgrade them?

    Sure, security can be improved. But no idea why topgrade deserves any blame here.

  • source
  • parent