View Single Post
Old 03-07-2015, 09:56 PM   #30
eschwartz
Ex-Helpdesk Junkie
eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.eschwartz ought to be getting tired of karma fortunes by now.
 
eschwartz's Avatar
 
Posts: 19,421
Karma: 85400180
Join Date: Nov 2012
Location: The Beaten Path, USA, Roundworld, This Side of Infinity
Device: Kindle Touch fw5.3.7 (Wifi only)
Quote:
Originally Posted by kovidgoyal View Post
@Queso: You are of course welcome to do whatever you find most comfortable. I do not support distro provided calibre packages for good reasons, but, if you prefer them, feel free to use them, the only caveat being that you wont get help from me

Personally, I find the idea that a small team of distribution package maintainers can effectively (and continuously!) review thousands of packages for bugs whether security or stability related, better than the developers that created the software to be rather incredible. It may well be true for software that is not actively maintained, but for software that is actively maintained, it just doesn't seem very likely.

And, in practice, I have found that distro maintainers introduce far more bugs than they fix. But, YMMV.
I am sure it is very useful simply because if a package finds its way into the repos in the first place, it can be assumed the package is not malicious (I hope it is safe to assume they get properly vetted the first time even if later they slack off due to overload). After that, feel free to use the developer recommended installation. After all, the only service the repos perform is vetting for downright malicious code (usually not applicable) and package management with debundled deps -- which can be a bad thing depending on the patches.
eschwartz is offline   Reply With Quote