به Nostr بپیوندید
2026-03-27 19:14:09 UTC
in reply to

arihi :bocchi_arch: :naima_padoru: :blobcatchristmastree: :ibrs2: :ene: on Nostr: i mostly do the same, if a popular distro i would use uses the source then it's ...

i mostly do the same, if a popular distro i would use uses the source then it's probably fine, otherwise i'll read the source myself. i checked some that were packaged just because they seemed like high-risk pieces of software but the software maintainer are likely doing a way better job and i obviously found nothing.

i'm wondering a bit how viable checking all the sources is though, because even after reading the full source i sometimes feel like i didn't understood it enough. for example bento4 took me several hours to read and contained a ton of cryptography so if something nasty was hiding there, jia tan style, how likely would i be to notice? it's so troublesome with tools that are complex, useful, but not popular enough for a capable maintainer to pick up.