Zoom

Oliver Grawert ogra at ubuntu.com
Mon Mar 30 15:11:04 UTC 2020


hi,
Am Montag, den 30.03.2020, 16:59 +0200 schrieb Liam Proven:
> On Mon, 30 Mar 2020 at 16:05, Oliver Grawert <ogra at ubuntu.com> wrote:
> > 
> > 
> > the problem with randomly dpkg -i'ing debs from some site is that
> > they
> > do never get updated in case upstream fixes a security issue ...

> ...adds its own repositories to your list and
> will so get updated from then on in.

i did not talk about repos (though if your system eats itself during a
release-to-releaase upgrade because some third-party secretly changed
your sources.list you will likely not be happy either)

i explicitly talked about using dpkg -i to install some downloaded deb
...

if you use a vendor repo you are indeed getting updates, but i'd always
inspect that repo very deeply first to make sure it does not contain
anything harmful or replaces actual system packages with their own...
(resulting in the above limbo where you might end up with a completely
broken system after upgrade because some external repo decided to
provide a patched libgtk or libX11 or whatever in their archive with an
epoch in the version number that makes downgrading hard etc etc)

IM(very personal)HO snap and flatpak are the future for third party (or
any other non-default) appsĀ 

ciao
	oli
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 181 bytes
Desc: This is a digitally signed message part
URL: <https://lists.ubuntu.com/archives/ubuntu-users/attachments/20200330/07f44442/attachment.sig>


More information about the ubuntu-users mailing list