Software repository: Difference between revisions

Content deleted Content added
Reverted 1 edit by 2600:1010:B156:8E67:0:E:6DD:4201 (talk): Vandalism
Tags: Twinkle Undo Mobile edit Mobile web edit
m rm contraction
 
(11 intermediate revisions by 10 users not shown)
Line 7:
== Overview ==
Many software publishers and other organizations maintain servers on the [[Internet]] for this purpose, either free of charge or for a subscription fee. Repositories may be solely for particular programs, such as [[CPAN]] for the [[Perl]] [[programming language]], or for an entire [[operating system]]. Operators of such repositories typically provide a [[package management system]], tools intended to search for, install and otherwise manipulate software packages from the repositories. For example, many [[Linux distribution]]s use [[APT (software)|Advanced Packaging Tool]] (APT), commonly found in [[Debian]] based distributions, or Yellowdog Updater, Modified ([[Yum (software)|yum]]) found in [[Red Hat]] based distributions. There are also multiple independent package management systems, such as pacman, used in [[Arch Linux]] and equo, found in [[Sabayon Linux]].
[[File:Zypper new repository package signing key screenshot.png|thumb|Example of a signed repository key (with [[ZYpp]] on [[openSUSE]])]]
 
As software repositories are designed to include useful packages, major repositories are designed to be [[malware]] free. If a computer is configured to use a [[digitally signed]] repository from a reputable vendor, and is coupled with an appropriate [[File system permissions|permissions system]], this significantly reduces the threat of malware to these systems. As a side effect, many systems that have these abilities do not need anti-malware software such as [[antivirus software]].<ref>[http://www.itmweb.com/essay503.htm itmWEB: Coping with Computer Viruses<!-- Bot generated title -->] {{webarchive |url=https://web.archive.org/web/20071014212824/http://www.itmweb.com/essay503.htm |date=October 14, 2007}}</ref>
 
Most major [[Linux distribution]]s have many repositories around the world that mirror the main repository.
 
In an enterprise environment, a software repository is usually used to store artifacts, or to mirror external repositories which may be inaccessible due to security restrictions. Such repositories may provide additional functionality, like access control, versioning, security checks for uploaded software, cluster functionality etc. and typically support a variety of formats in one package, so as to cater for all the needs in an enterprise, and thus aiming to provide a single point of truth. Popular examples are JFrog Artifactory,<ref>{{Cite web|url=https://www.wikieduonline.com/wiki/JFrog_Artifactory|title=JFrog Artifactory - wikieduonline|access-date=2021-04-25|archive-date=2021-03-05|archive-url=https://web.archive.org/web/20210305194720/https://www.wikieduonline.com/wiki/Jfrog_artifactory|url-status=live}}</ref><ref>{{Cite web|url=https://jfrog.com/artifactory/|title=Artifactory - Universal Artifact Management|access-date=2021-04-25|archive-date=2021-05-01|archive-url=https://web.archive.org/web/20210501195901/https://jfrog.com/artifactory/|url-status=live}}</ref> Nexus repository<ref>{{Cite web|url=https://www.sonatype.com/products/repository-pro|title=Nexus Repository &#124; Software Component Management|access-date=2021-04-25|archive-date=2021-04-25|archive-url=https://web.archive.org/web/20210425085038/https://www.sonatype.com/products/repository-pro|url-status=live}}</ref> and Cloudsmith,<ref>{{Cite web|url=https://www.cloudsmith.com/|title=Cloudsmith artifact repository|access-date=2023-09-11|archive-date=2023-07-16|archive-url=https://web.archive.org/web/20230716121932/https://cloudsmith.com/|url-status=live}}</ref> a cloud-based product.
 
At client side, a package manager helps installing from and updating the repositories.
 
At server side, a software repository is typically managed by source control or repository managers. Some of the repository managers allow to aggregate other repository ___location into one URL and provide a caching proxy. When doing continuous builds many artifacts are produced and often centrally stored, so automatically deleting the ones which are not released is important.
 
== Package management system vs. package development process ==
Line 32 ⟶ 28:
Very few people have the ability to test their software under multiple operating systems with different versions of the core code and with other contributed packages they may use. For the [[R (programming language)|R programming language]], the [[CRAN (R programming language)|Comprehensive R Archive Network (CRAN)]] runs tests routinely.
 
To understand how this is valuable, imagine a situation with two developers, Sally and John. Sally contributes a package A. Sally only runs the current version of the software under one version of Microsoft Windows, and has only tested it in that environment. At more or less regular intervals, CRAN tests Sally's contribution under a dozen combinations of operating systems and versions of the core R language software. If one of them generates an error, she gets that error message. With luck, that error message details may provide enough input to allow enable a fix for the error, even if she cannot replicate it with her current hardware and software. Next, suppose John contributes to the repository a package B that uses a package A. Package B passes all the tests and is made available to users. Later, Sally submits an improved version of A, which unfortunately, breaks B. The autochecks make it possible to provide information to John so he can fix the problem.
 
This example exposes both a strength and a weakness in the R contributed-package system: CRAN supports this kind of [[automated testing]] of contributed packages, but packages contributed to CRAN need not specify the versions of other contributed packages that they use. Procedures for requesting specific versions of packages exist, but contributors might not use those procedures.
Line 108 ⟶ 104:
|-
| [[Python (programming language)|Python]]
| [[Setuptools]], Poetry<ref>{{Cite web|url=https://python-poetry.org|title=Poetry|website=python-poetry.org|access-date=2024-05-22|archive-date=2024-05-22|archive-url=https://web.archive.org/web/20240522033832/https://python-poetry.org/|url-status=live}}</ref>
| [[Setuptools]]
| [[Python Package Index|PyPI]]
| [[pip (package manager)|pip]], [[EasyInstall]], [[Python Package Manager|PyPM]], [[Anaconda (Python distribution)|Anaconda]]
|
|
Line 188 ⟶ 184:
|-
|[[Homebrew (package manager)|Homebrew]]
|A package installer for MacOS that allows one to install packages Apple didn'tdid not<ref>{{Cite web|url=https://brew.sh/|title=Homebrew|website=Homebrew|language=en|access-date=2019-11-22|archive-date=2022-10-05|archive-url=https://web.archive.org/web/20221005114956/https://brew.sh/|url-status=live}}</ref>
|-
|[[vcpkg]]
Line 201 ⟶ 197:
 
== Repository managers ==
In an enterprise environment, a software repository is usually used to store artifacts, or to mirror external repositories which may be inaccessible due to security restrictions. Such repositories may provide additional functionality, like access control, versioning, security checks for uploaded software, cluster functionality etc. and typically support a variety of formats in one package, so as to cater for all the needs in an enterprise, and thus aiming to provide a single point of truth. PopularOne examplesexample areis JFrog[[Sonatype Artifactory,<ref>{{CiteNexus web|url=https://wwwRepository]].wikieduonline.com/wiki/JFrog_Artifactory|title=JFrog Artifactory - wikieduonline|access-date=2021-04-25|archive-date=2021-03-05|archive-url=https://web.archive.org/web/20210305194720/https://www.wikieduonline.com/wiki/Jfrog_artifactory|url-status=live}}</ref><ref>{{Cite web|url=https://jfrog.com/artifactory/|title=Artifactory - Universal Artifact Management|access-date=2021-04-25|archive-date=2021-05-01|archive-url=https://web.archive.org/web/20210501195901/https://jfrog.com/artifactory/|url-status=live}}</ref> Nexus repository<ref>{{Cite web|url=https://www.sonatype.com/products/repository-pro|title=Nexus Repository &#124; Software Component Management|access-date=2021-04-25|archive-date=2021-04-25|archive-url=https://web.archive.org/web/20210425085038/https://www.sonatype.com/products/repository-pro|url-status=live}}</ref> and Cloudsmith,<ref>{{Cite web|url=https://www.cloudsmith.com/|title=Cloudsmith artifact repository|access-date=2023-09-11|archive-date=2023-07-16|archive-url=https://web.archive.org/web/20230716121932/https://cloudsmith.com/|url-status=live}}</ref> a cloud-based product.
 
At server side, a software repository is typically managed by source control or repository managers. Some of the repository managers allow to aggregate other repository ___location into one URL and provide a caching proxy. When doing continuous builds many artifacts are produced and often centrally stored, so automatically deleting the ones which are not released is important.
 
=== Relationship to continuous integration ===
Line 250 ⟶ 249:
* [[dpkg]]
* [[Simtel]]
* [[APTonCD]]
{{div col end}}