~alpine/users

Re: Alpine Main Packages Lists

Details
Message ID
<D4PMQF0VJJ9N.2PNQCQTERT41F@pwned.life>
DKIM signature
missing
Download raw message
On Mon Oct 7, 2024 at 3:40 PM CEST, Nigel Hopper wrote:
> Hi
>
> I?m part of a team that audit software and one of the things that we have to do is differentiate operating system packages from when they are part of the core operating system and when they are added as part of the build from something else.
>
> We refer to these as Main OS (part of the core OS) and Non-main (added on top of the core OS).
>
> Alpine has been a bit of a challenge, but would like to know I we could use either of the following links to give us an accurate list of the Alpine Main OS packages. These would be for 3.20
>
> https://alpine.pkgs.org/3.20/alpine-main-x86_64/
> https://pkgs.alpinelinux.org/packages?name=&branch=v3.20&repo=main&arch=x86_64&origin=&maintainer=&flagged=

If you want reliable information, it's best not to parse a website but
use the APKINDEX from Alpine mirrors (e.g.
https://dl-cdn.alpinelinux.org/alpine/v3.20/main/x86_64/APKINDEX.tar.gz).

It's what pkgs.alpinelinux.org uses to generate data and also what apk
itself uses to update package lists.

>
> Technically the ?same site? but there are differences between these even though they are the same release.
>
> gcompat
> java-cacerts
>
> According to these lists, the first package above is on the list, but the second is not. Based on this, we would likely make gcompat as a Main OS package and java-cacerts is a Non-main operating system package.
>
> Are either of these lists an accurate representation of the Main OSs for Alpine 3.20.
>
> Many thanks.
>
>
> Nigel Hopper
> Security Consultant: Cybersecurity Assessment & Response Services
> Open Source Software Auditor
> Advisory Software Engineer
> QSE Development Top Gun
>
> Unless otherwise stated above:
>
> IBM United Kingdom Limited
> Registered in England and Wales with number 741598
> Registered office: Building C, IBM Hursley Office, Hursley Park Road, Winchester, Hampshire SO21 2JN
Reply to thread Export thread (mbox)