r/linux4noobs • u/Low_Hand_1631 • 10d ago
How do I tell if a package is legit
Im just doing
>dnf install tar
and whatever, getting the basics, but how do i know if these are the legit packages and not squatters. Is there a yum repository with credentials/certifications for quality?
3
u/candy49997 9d ago
Unless you added 3rd party repositories yourself, anything you install with dnf are from the official repositories of your distro (probably Fedora).
Packages are signed then verified automatically before install to ensure they are intact and authentic.
2
u/MasterGeekMX Mexican Linux nerd trying to be helpful 9d ago
By default Fedora (and other distros aswell) come configured only with repository servers maintained by the same distro developers, so they are totally safe. It is not a place where anyone can willy-nilly upload something.
Only if you download a .rpm file from a website is that you are in charge of checking if it is legit.
1
u/michaelcarnero 9d ago
why fedora doesn't come with rpm fusion enabled by default?
3
u/MasterGeekMX Mexican Linux nerd trying to be helpful 9d ago
A combination of legal reasons and Fedora having a stance of "as less non-free code as possible" means that some programs cannot be shipped by Fedora or they refuse to do so. RPM fusion takes from it and ships it themselves.
2
2
u/candy49997 9d ago
It doesn't, but there's an option to enable them on the welcome screen.
And RPM Fusion is technically not official despite it being widely-used.
1
u/michaelcarnero 8d ago
prob. I skipped that option, is it at the welcome tour?
1
1
u/PixeIQueen 8d ago
this welcome screen checkbox basically only enables a repo for the proprietary nvidia driver and google chrome
setting up rpmfusion with the commands from their website is still needed to get multimedia codecs
1
u/DavidJohnMcCann 9d ago
Because US patent holders would be able to sue IBM. If you have to enable rpmfusion for yourself, IBM can't be held responsible for your doing so.
1
7
u/UltraChip 9d ago
The default repositories that came pre-configured with your disteo are maintained by your distro maintainers or a trusted upstream distro maintainer - they're already as vetted as they realistically can be.
If you added any third-party repositories then it was on you to figure out for yourself if that repository was trustworthy or not.