in reply to Re^5: Meaning of XS object version
in thread Meaning of XS object version
I think the question you should be asking is:
How do I manage my non-OS perl installation (via perlbrew for example) with as little manual intervention as possible, as if I was updating it via my package manager?Edit:
Sorry I missed this:After all our monthly patch cycles would pick up security items withou +t us having to monitor and manage these on our own.
CPAN may not be the best for security reviews of modules.
bw, bliako
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^7: Meaning of XS object version (Package Manager Security References - example building Perl securely from source)
by eyepopslikeamosquito (Archbishop) on Jul 23, 2023 at 00:48 UTC | |
> on our move to Red Hat GNU/Linux we looked forward to handing off that responsibility to the package manager (rpm via yum/dnf) Good catch! The OP has been a bit vague about their Security Requirements. Package Manager and CPAN Security Package Manager and CPAN Security seems to be a difficult topic. Some references:
Example: build perl v5.38 securely from source on Ubuntu An example build and install of the latest perl v5.38.0 from source on my Ubuntu Linux VM using cpanm follows. Do all steps below as non-root as a further precaution against accidentally mangling your system perl.
Next install cpanm using the cpan command:
to install the cpanm executable to the perl's bin path (e.g. ~/perl5/perlbrew/bin/cpanm). In my example, that would be: $HOME/localperl/bin/cpanm (note: I switched from $HOME/localperl/bin to $HOME/my/p5380/bin after this node was written to conveniently have multiple versions of perl simultaneously installed to my $HOME directory). (Update: while using the cpan command (as above) seems best, see Building Perl and CPAN Modules Securely from Source for alternative ways to install cpanm) Then install Module::Signature from CPAN using the cpanm command:
With that done, an example installing the CPAN Roman module more securely via cpanm's --verify option:
Note that cpanm's --verify option verifies the integrity of distribution files retrieved from CPAN using CHECKSUMS file, and SIGNATURES file (if found in the distribution). To uninstall Roman:
After installation, ensure your local perl is ahead of system perl in your path by updating your .profile adding at the end:
Update: see also Re^2: THREE new perl releases [Updated releases!] - build perl v5.38.2 from source Building Perl from Source References
Package Manager References
See Also
Updated: Added "Example: build perl v5.38 securely from source on Ubuntu" section (thanks hippo for motivating me :). Added sha256sum check of perl-5.38.0.tar.gz. Added more references. Added Package Manager References section. | [reply] [d/l] [select] |