emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: security of the emacs package system, elpa, melpa and marmalade


From: Matthias Dahl
Subject: Re: security of the emacs package system, elpa, melpa and marmalade
Date: Mon, 30 Sep 2013 17:12:56 +0200
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.0

Hello Richard...

> I think that we should warn users that it is risky to use packages
> from archives that don't supervise the code that gets put in them, or
> that don't use signing.

+1

But imho, this would also include ELPA because there is not really a
control process in place. A mail gets sent that some person from the
community needs to thoroughly read/check. There is no guarantee that
someone will actually do this.

So long,
Matthias

-- 
Dipl.-Inf. (FH) Matthias Dahl | Software Engineer | binary-island.eu
 services: custom software [desktop, mobile, web], server administration



reply via email to

[Prev in Thread] Current Thread [Next in Thread]