[ale] Blind Debian updates?

James Sumners james.sumners at gmail.com
Mon Nov 20 09:40:04 EST 2006


I can not stress enough how bad this idea is. Just one example: what
if the repository you are using gets compromised and you are
automatically updating from it every day? That isn't good.

I don't have the time to login to my servers and check for updates
either. That's why I wrote the script I have posted at
http://james.roomfullofmirrors.com/code.php to check for available
updates and send me an email. The email it sends isn't pretty, but it
tells me what packages are out-of-date. I can decide from there if I
need to immediately login and update the system, or if I can wait a
while.

On 11/20/06, John Wells <jb at sourceillustrated.com> wrote:
> Guys,
>
> I have a number of Debian servers that I don't get to check in on as much
> as I'd like. I'd like to make sure these are kept as up to date as
> possible regarding security patches, and am considering setting up a cron
> job to run "apt-get upgrade" on a nightly basis.
>
> Anyone else doing this? What is your exact setup? Any caveats?
>
> Thanks, as always. Hope you're all doing well.
>
> John

-- 
James Sumners
http://james.roomfullofmirrors.com/

"All governments suffer a recurring problem: Power attracts
pathological personalities. It is not that power corrupts but that it
is magnetic to the corruptible. Such people have a tendency to become
drunk on violence, a condition to which they are quickly addicted."

Missionaria Protectiva, Text QIV (decto)
CH:D 59



More information about the Ale mailing list