Re: What is the best way to manage 3rd party debs?



Aniruddha wrote:
On Tue, 2008-08-12 at 14:41 -0400, Hubert Chathi wrote:
No, they can't. Not without your expressed consent...
[...]

They can't, if they just use the normal Debian archive contents.
However, packages can do all sorts of things via installation scripts.

Then again, the package could hide all sorts of things. (Think:
trojaned binary.) If you don't trust your package source, you shouldn't
install their packages.

I'm not worried about a malicious packages. I am more concerned that a
3rd party deb damages the system by mistake.

By default I install all 3rd party binary and source packages in a
~/programs folder. That way I don't have to worry about fubaring my
system.

I like to do something like that for deb packages too. Who knows a good
solution?


If 3rd party deb doesn't contain 'Replaces' field, dpkg will refuse any try to break any
file owned by existing packages.

--
Eugene V. Lyubimkin aka JackYF, Ukrainian C++ developer.

Attachment: signature.asc
Description: OpenPGP digital signature



Relevant Pages

  • Re: Complete Linux Recording Package Ready To Roll.
    ... How to install Rehmudi-2.0 ... if you don't have any sound, ... dependencies of Agnula Packages ... ... from the new kernel. ...
    (comp.os.linux.misc)
  • FS: Complete Linux Recording Package Ready To Roll.
    ... How to install Rehmudi-2.0 ... if you don't have any sound, ... dependencies of Agnula Packages ... ... from the new kernel. ...
    (comp.os.linux.misc)
  • Which debian sources to use to install to Knoppix 4.0.2?
    ... running into a problem when I install software to version 4.0.2 that I ... Check out the list of extra packages to be installed, ... akregator ark cupsys cupsys-bsd cupsys-client gcc-4.0-base gs-common ... kdepim-kfile-plugins kdepim-kio-plugins kdeprint kdesktop kdessh kdf ...
    (comp.os.linux.misc)
  • Apt Gone Mad?-Or Is It Me?-Expert Help Needed
    ... So tried to upgrade OO to 2.0 but Apt refused to do so. ... Aptitude doesn't show anything but Wajig shows unmet dependency for kdelibs-data. ... The following packages are unused and will be REMOVED: agsync arson barcode brahms cdda2wav cddb digikam digikamimageplugins gmessage guarddog guidedog hotswap-gui hotswap-text i2e id3v2 kbarcode kbear kbiff kdebase-dev kdirstat kile kimdaba klog klogic kmymoney2 knetfilter knutclient komba2 kover kprof kpsk krusader ksimus ksimus-boolean ksimus-datarecorder ksimus-floatingpoint ksocrat ksocrat-data kvdr kvirc kvirc-data kvirc-doc kwavecontrol kxmleditor lesstif2 libdynamite libimlib2-dev libkonq4-dev libmimedir liborange ... ChatagnierL-Home:/temp# wajig install openoffice.org Reading Package Lists... ...
    (Debian-User)
  • Re: Debian or Ubuntu Dilemma
    ... Debian Stable < Ubuntu < Debian Testing/Unstable < Any Distro w/mutt packaging ... You'll eventually have to compile a few packages with any distro (from Debian ... Ubuntu seems to be a good balance if its default install does almost ...
    (Debian-User)