Slashdot Mirror


Package Signing Comes To Pacman and Arch Linux

fwarren writes "One of the main complaints heard around here on why some Slashdotters don't run Arch Linux is that the packages are not signed. Fear no more: Arch Linux and Pacman now allow for package signing."

8 of 103 comments (clear)

  1. Arch Linux: what's the differentiating factor? by Anonymous Coward · · Score: 4, Interesting

    What does Arch bring to the table?

    Debian has a minimal install option, is committed to freedom, has an awesome package manager, has tons of packages available, and has multiple release tracks that allow one to stay cutting edge should one wish.

    RedHat is commercially supported.

    CentOS is the free version of RedHat.

    SLES is commercially supported, with a deal with Microsoft to interoperate.

    Ubuntu is Debian made easier.

    Gentoo is for people who like to recompile software for their hardware.

    I get all of the above distros. I don't run them all myself -- especially not gentoo -- but I understand why some people do.

    What's the point of Arch? I poked at the website and wikipedia pages, but don't see an explanation of what it gives you over, say, a base Debian install.

    Note: this is not intended as a troll. I'm curious as to what Arch brought to the table. Why was it introduced? I'm sure there's an answer, just curious what.

    1. Re:Arch Linux: what's the differentiating factor? by some_guy_88 · · Score: 4, Informative

      My favourite Arch feature is the AUR (Arch User Repository) where anyone can submit their own packages which other uses can then install.

      Because of the AUR, Arch is more likely to have a package for some given obscure application that Debian would be missing. Also, these packages are kept up to date to a greater extent than you'll see on Debian. Finally they're all in one place where as you don't have to constantly add repositories to your package manager's repo list.

    2. Re:Arch Linux: what's the differentiating factor? by Hatta · · Score: 4, Informative

      Great documentation and vanilla packages. That about sums it up. It's like Slackware with improved package management.

      I've been running systems built from Debian base for about a decade. Recently I kept running into the Arch wiki when I wanted to solve a problem. e.g. if I want to reenable ctrl-alt-backspace in Xorg. If I google that, I get a page full of shitty Ubuntu related solutions that depend on extra packages or gui configuration tools.

      But there's one result that sticks out. The Arch wiki provides a nicely organized richly linked list of things you might want to configure, and how to configure them. This is how you collect and present useful information. I figured, if I find myself consistantly using the documentation for a distro, maybe I should check out the actual distro.

      So I still use Debian on most of my systems, but have thrown Arch on a couple for fun. It's easy, it works, and it doesn't feel as crufty as Debian does. Package signing will make it a contender for real work. Yay Arch!

      --
      Give me Classic Slashdot or give me death!
    3. Re:Arch Linux: what's the differentiating factor? by substance2003 · · Score: 5, Insightful

      I think the only thing you missed was that it's a rolling release OS meaning that unlike other distros. You never need to reinstall it unless you mess up.
      That to me has been the most important feature for me as I found it would get old to have to reinstall Fedora every 6 to 12 months to get access to the latest bleeding edge software.

      As one reviewer said, this OS is always fresh.

  2. Comment removed by account_deleted · · Score: 5, Informative

    Comment removed based on user account deletion

  3. Re:FRIST by K.+S.+Kyosuke · · Score: 4, Funny

    Warning. The parent post in unsigned and may have been forged.

    --
    Ezekiel 23:20
  4. Whew.... by liquidweaver · · Score: 4, Funny

    I've been using Arch for years, and the constant flow of virii and rootkits that were deluging me might finally go away!
    With all the recent news of linux package repositories being the main vector of all these advanced persistent threats my CPO (Chief Pentest Officer) has been telling me about, I can now breath a sigh of relief.

    --
    mov ah, 4ch
    int 21h
  5. I just live on the edge by mshenrick · · Score: 5, Funny

    I feel like such a fearless badman for running arch linux before the packages were signed