Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With most package managers you can review package sources (e.g. "choco info" for chocolatey or "brew info" / "brew edit" for homebrew).

As for threat model it comes down to whether using package management poses larger risk than doing everything manually and risking running a range of outdated packages.



Yes, fair points. It's always a judgement call - which is the lesser of two evils...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: