![]() |
Differences between Harbour and OpenRepos
Hi everybody, I've been using Jolla for almost a week now, and have not installed anything outside of harbour.
There're a few apps I'd like to try, on OpenRepos, but still did not get what are the benefit of this repository over Jolla.
|
Re: Differences between Harbour and OpenRepos
1. Yes. AFAIK it is faster to release a new version of a program on open repos. So you can better test unstable beta versions. In the Jolla store every program has to be aproved...
|
Re: Differences between Harbour and OpenRepos
Quote:
Quote:
Quote:
|
Re: Differences between Harbour and OpenRepos
Quote:
Quote:
Quote:
Refer to publisher reputation, application rating, and comments as measurement tool In general words: if someone with bad intensions uploads malware, it can damage/compromise your jolla/information. This also can happen with official store, since there is only binary package upload. |
Re: Differences between Harbour and OpenRepos
Quote:
Also AFAIK rpms from OpenRepos are not signed so if some attacker gets access to the server, he can infect popular rpms without developers knowing. So, good intentions and given Jolla store policies and such really useful, but potentially big security hole. |
Re: Differences between Harbour and OpenRepos
Quote:
Best way to look at it is: treat openrepos as extras-devel (hopefully source submissions will become required and only built on OR things get there, like the -devel from fremantle, so you can always download the source and build it yourself after review if you have doubts), if you recognize the author and trust him, no problem, if not, there are risks involved |
Re: Differences between Harbour and OpenRepos
Harbour QA does not quarantee application is not malicious. It can't unless they start to require source and review it. That would be too costly even in theory and it would kill the whole Jolla (store).
I hope openrepos will never start requiring source code submission or build on as that would only cause yet another "open repository" to popup. I know there are risks and I know typical consumer does not recognize those risks. |
Re: Differences between Harbour and OpenRepos
Openrepos will have types of repositories: public, paid and obs. first two are uploaded as rpm, sources can/not be provided, last one is packages synced with author obs repo. and in all repositories packages with negative marks will be unpublished automatically.
you need to understand, there are many ideas about openrepos, but cant be implemented too fast :) |
All times are GMT. The time now is 13:34. |
vBulletin® Version 3.8.8