Freedom is a synthetic enterprise, not a natural gift

Glory to the ghosts of us

  • 363 Posts
  • 1.21K Comments
Joined 6 years ago
cake
Cake day: November 25th, 2020

help-circle






  • how would nix be affected by an attack like the one in the aur? nix packages its own dependencies, which are then packaged into other packages. the attack on the aur was possible because some software called for a library to be downloaded somewhere and npm was affected which ended up affecting the aur. for it to work on nix someone would have to upload a malicious package into the nixpkgs, which im not saying its impossible, but at the bare minimum there’s a bigger barrier than basically 0 compared to the aur.