~alpine/users

1

Alpine Main Packages Lists

Details
Message ID
<DS0PR15MB569879367894D7C1DF19FD54C57D2@DS0PR15MB5698.namprd15.prod.outlook.com>
DKIM signature
missing
Download raw message
Hi

I?m part of a team that audit software and one of the things that we have to do is differentiate operating system packages from when they are part of the core operating system and when they are added as part of the build from something else.

We refer to these as Main OS (part of the core OS) and Non-main (added on top of the core OS).

Alpine has been a bit of a challenge, but would like to know I we could use either of the following links to give us an accurate list of the Alpine Main OS packages. These would be for 3.20

https://alpine.pkgs.org/3.20/alpine-main-x86_64/
https://pkgs.alpinelinux.org/packages?name=&branch=v3.20&repo=main&arch=x86_64&origin=&maintainer=&flagged=

Technically the ?same site? but there are differences between these even though they are the same release.

gcompat
java-cacerts

According to these lists, the first package above is on the list, but the second is not. Based on this, we would likely make gcompat as a Main OS package and java-cacerts is a Non-main operating system package.

Are either of these lists an accurate representation of the Main OSs for Alpine 3.20.

Many thanks.


Nigel Hopper
Security Consultant: Cybersecurity Assessment & Response Services
Open Source Software Auditor
Advisory Software Engineer
QSE Development Top Gun

Unless otherwise stated above:

IBM United Kingdom Limited
Registered in England and Wales with number 741598
Registered office: Building C, IBM Hursley Office, Hursley Park Road, Winchester, Hampshire SO21 2JN
Details
Message ID
<20241007160102.6c19218e@blueselene.com>
In-Reply-To
<DS0PR15MB569879367894D7C1DF19FD54C57D2@DS0PR15MB5698.namprd15.prod.outlook.com> (view parent)
DKIM signature
missing
Download raw message
On Mon, 7 Oct 2024 13:40:21 +0000
Nigel Hopper <nigel_hopper@uk.ibm.com> wrote:

> Alpine has been a bit of a challenge, but would like to know I we
> could use either of the following links to give us an accurate list
> of the Alpine Main OS packages. These would be for 3.20
> 
> https://alpine.pkgs.org/3.20/alpine-main-x86_64/
> https://pkgs.alpinelinux.org/packages?name=&branch=v3.20&repo=main&arch=x86_64&origin=&maintainer=&flagged=
> 
> Technically the ?same site? but there are differences between these
> even though they are the same release.

Not the same site, pkgs.org isn't managed by the people on Alpine
Linux. pkgs.alpinelinux.org is the authoritative source if you want a
list of packages on the main repo.

-- 
Current PGP KeyID: 0AFB427F1800FD89751C4035292228735AE707FF

https://blueselene.com/pgp-archive/0AFB427F1800FD89751C4035292228735AE707FF/key.pub
Reply to thread Export thread (mbox)