PDA

View Full Version : [ubuntu] FreeBSD's portaudit on Ubuntu?



djteej
May 4th, 2009, 02:45 PM
FreeBSD's portaudit checks installed packages for known vulnerabilities and generates reports including references to security advisories.

Has anyone managed to port this package for Ubuntu or does anyone know of an equivalent for Ubuntu? This package is an excellent addition, especially for production servers.

windependence
May 5th, 2009, 03:30 AM
Unfortunately I don't think there's anything like that for Linux. Why not just run FreeBSD? That would be my preference. I only run Linux when necessary.

-Tim

djteej
May 7th, 2009, 08:27 PM
I was reading the Ubuntu Documentation and found the following:


"Another useful package is apticron. apticron will configure a cron job to email an administrator information about any packages on the system that need updated as well as a summary of changes in each package."

I haven't had the opportunity to evaluate this as of yet, but it sounds promising.

windependence
May 7th, 2009, 11:40 PM
Good deal, and good luck!

-Tim

dreamgear
September 21st, 2009, 07:55 PM
Hi. I'm posting under this thread because I am also looking for portaudit-like functionality.

Part of the value proposition for Jeos and the LTS releases is "fewer updates". But what is the best way to determine when in fact there is a critical (particularly security-related) update?

FakeOutdoorsman
September 21st, 2009, 08:30 PM
Hi. I'm posting under this thread because I am also looking for portaudit-like functionality.

Part of the value proposition for Jeos and the LTS releases is "fewer updates". But what is the best way to determine when in fact there is a critical (particularly security-related) update?

I subscribe to the security mailing list of another distribution and your equivalent would be ubuntu-security-announce (https://lists.ubuntu.com/archives/ubuntu-security-announce/). This notifies me of any security update and then I upgrade the system manually. I upgrade manually because certain package upgrades may disrupt my system.

If you prefer RSS, Ubuntu has that option as well at Ubuntu Security Notices (http://www.ubuntu.com/usn).

wigwam47
March 30th, 2011, 03:15 PM
apticron and rss are good, but to save one's time it would be better to see ONLY security issues (not all upgradable packages) and ONLY issuses of installed packages (not all ubuntu packages) - just like portaudit works.

still not found any sw with similar funcionality?