Repositories of repositories with meta information
The idea is to maintain a list of known repositories, with meta information about each of them, like a safety rate given by users, which distribution/
For security, it would obviously require a master key to sign keys. This would permit to add a repository more easily too, by only selecting it in a list, then the deb line and the key are automatically added.
A graphical interface should be provided, showing the list of repositories with meta informations, featuring an integrated rating system and critical safety reporting system when a user detects a potential malicious package.
Then when one clicks on "add this repository", an appropriate message is displayed, like :
- "This repository has been fully approved by most users (nb approved / nb total) but not by the ubuntu team (s/ubuntu team/repository master/) yet"
- "This repository has been fully approved by the ubuntu team (however, it is not officially supported)"
- "This repository is said to be very unstable and may crash your system"
- "This repository has been reported as dangerous, you'd better wait while the ubuntu team examines the report"
- "This repository contains closed source software. This is a potential risk since nobody but the authors can check it's safety" ;-)
- "This repository is for another architecture (hppa-64)"
- "This repository is for a prior version of ubuntu"
- "This repository is for another distribution (debian testing)"
etc...
What do you think of this proposal? I think it is a good way to simplify a lot of things for users who want third party software.
Blueprint information
- Status:
- Not started
- Approver:
- None
- Priority:
- Undefined
- Drafter:
- None
- Direction:
- Needs approval
- Assignee:
- None
- Definition:
- New
- Series goal:
- None
- Implementation:
- Unknown
- Milestone target:
- None
- Started by
- Completed by