Re: How secure is the openSUSE Build Service?



Hi,

<http://download.opensuse.org/repositories/> Are those really third
party repositories?
As with any third party repository/tree/source the usual caveat apply:
You are on your own.

Ed

On 10/31/07, Aniruddha <mailing_list@xxxxxxxxx> wrote:
With the releae of openSUSE 10.3, openSUSE introduced
'1-Click Install' . However openSUSE only has security support for it's
oss and non-oss repositories.

How great of a security risk is adding third-party repositories which
you can hardly verify ( http://download.opensuse.org/repositories/ )?
What are the risks of getting rootkits and/or security exploits.

Is openSUSE's approach more risky then Gentoo/FreeBSD which provides
security fixes for all packages in their tree?



--
Regards,

Aniruddha