logoalt Hacker News

bfleschyesterday at 12:59 PM1 replyview on HN

AFAIK a lot of linux packet repositories are http-only as well. Convenient for tracking what package versions have been installed on a certain system.


Replies

arghwhatyesterday at 1:27 PM

They usually support both, but important to note that HTTPS is only used for privacy.

Package managers generally enforce authenticity through signed indexes and (directly or indirectly) signed packages, although be skeptical when dealing with new/minor package managers as they could have gotten this wrong.

show 1 reply