• 8 Posts
  • 45 Comments
Joined 25 days ago
cake
Cake day: February 28th, 2026

help-circle



  • Hi! Thank you for your reply. So, if I understood correctly, whenever I click on “Install from Debian/GNU Linux” on Discover I am getting software directly from Debian’s repository (thus, a “repository” in the sense that it’s a place where this software is stored and can be retrieved); same thing when clicking on “Install from Flathub” for a Flatpak from Flathub. This does seem like the safest approach in the sense that it’s the less risky one and, if malware did slip through, such as the XZ backdoor, at least it would not have been due to a personal mistake of mine, but a general one which would’ve affected much more people too.

    This, in turn, is different from APT, which is not Debian’s repository, but Debian’s package manager. So, technically, I could write “sudo apt install (anything)” to get any piece of software from Debian’s repository indeed, but I could also use that command to get software from somewhere else also in the form of a Deb package but which would not have come from Debian itself.

    Did I get this right?

    Thanks a bunch.