Re: Relative security of Community repos and packages

Поиск
Список
Период
Сортировка
От Christophe Pettus
Тема Re: Relative security of Community repos and packages
Дата
Msg-id 68B44B4E-1C13-4262-9F6F-C79601C72102@thebuild.com
обсуждение исходный текст
Ответ на Relative security of Community repos and packages  ("pbj@cmicdo.com" <pbj@cmicdo.com>)
Ответы Re: Relative security of Community repos and packages
Список pgsql-www

> On Jul 28, 2021, at 11:26, pbj@cmicdo.com wrote:
> Currently involved in a discussion about security of Postgres packages from various sources.  I'm strongly advocating
thatwe get our packages directly from PGDG. 
>
> Would Postgres packages from Red Hat repos (and I guess we could include EDB, 2nd Quadrant, Crunchy...) be considered
moresecure from being hacked than those from the PGDG repos? 

While I have nothing bad to say about the other repo sources, every other repo (AFAIK) pulls from the community repos,
sothere's no reason that they would be *more* security than the community sources.  The Infra team takes build chain
andhosting security very seriously, and I would say that you are as safe with the community repos as you would be with
anyother source. 


В списке pgsql-www по дате отправления:

Предыдущее
От: Adrian Klaver
Дата:
Сообщение: Re: Relative security of Community repos and packages
Следующее
От: Dave Page
Дата:
Сообщение: Re: Relative security of Community repos and packages