199
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 08 Sep 2023
199 points (97.2% liked)
Open Source
31365 readers
985 users here now
All about open source! Feel free to ask questions, and share news, and interesting stuff!
Useful Links
- Open Source Initiative
- Free Software Foundation
- Electronic Frontier Foundation
- Software Freedom Conservancy
- It's FOSS
- Android FOSS Apps Megathread
Rules
- Posts must be relevant to the open source ideology
- No NSFW content
- No hate speech, bigotry, etc
Related Communities
- !libre_culture@lemmy.ml
- !libre_software@lemmy.ml
- !libre_hardware@lemmy.ml
- !linux@lemmy.ml
- !technology@lemmy.ml
Community icon from opensource.org, but we are not affiliated with them.
founded 5 years ago
MODERATORS
Scoop looks cute, but if I'm reading it right the manifest (where the pre-install and hash is) isn't itself signed. It presents some neat-o attack space in addition to the supply-chain attack (always, always cringe whenever installers go out and automatically find dependencies for you without you firmly specifying source) make me think this one has some work to do yet. By comparison, prior art for both of those existed in Linux land for about 2 decades, along with simple local repo caching.
I see there's talk of merging or feeding into either choco or winget already, despite the loss of superior layout it has over choco or the superior packaging and management it has over winget .
Scoop is neat, but it could look to its counterparts for improvement potential.