The software in a deb repository is compiled. You would not notice a (present or future) malicious modification of it (e.g., a backdoor). In the related deb-src repository, there is the source code. However, as far as I understand, nothing guarantees that the compiled packages are built from these sources. If you want to build from the source, why not taking it from the upstream developers?

To be clear: I am not claiming the “GNU Octave” team on Launchpad is not trustworthy. I am just pointing out that you need to trust this additional actor if you go for the convenience of the PPA (in particular the automatic updates), rather than whatever the upstream developers distribute. Often times, upstream developers administrate the PPA. It does not seem to be the case here.

Reply via email to