Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Best I can tell, none of the versions are pinned.

From your link, everything is pinned? So a theoretical exploit in a future release of package is not going to exist in this immutable release https://github.com/ublue-os/bazzite/releases/tag/42.20250417



Right but everytime a new immutable release is created, it automatically pulls the latest version of every package. It's not a manual change of package versions.


I mean that's the big lie isn't it? We all know no one is actually looking at these.

Every system which tells me how immutable it is then shows me it's automatic version bump script or something.


The current term being used is "atomic" for this reason.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: