Episode 266 - PowerScripting Podcast - Matt Wrock from Microsoft on BoxStarter

A Podcast about Windows PowerShell.

In This Episode

Tonight on the PowerScripting Podcast, we talk to Matt Wrock about BoxStarter



Guest - Matt Wrock



Chatroom Highlights:

[22:43:30] <Jaykul> FWIW, my 2c: I think a "moderated" feed (where you just trust the core chocolatey team to review packages, instead of trusting all the authors) is the answer to "trust" -- the idea being the core team says that yes, this module just downloads and installs "the real product" that it claims to.

<Jaykul> ## Have you heard rumors that chocolatey may move away from nuget?

<Jaykul> ## Are you involved in the chocolatey community at all?

<Jaykul> ## Are you (un)happy/neutral that Chocolatey has moved their lib/install folders to C:\ProgramData

<Jaykul> ## Are you (un)happy/neutral about the idea of expecting users to be "elevated" when running cinst?

<Jaykul> ## Does that mean boxstarter only works on machines that have access to the public internet?  <-- I know it does, just want to bring it up

<Jaykul> ## What do you think about a "Moderated" feed like NuGet has for Microsoft

<Jaykul> ## Isn't virus scanning the package mostly useless, since the package is just a script that downloads from the web? Would you guarantee that the install.ps1 can't download anything without scanning it?

<Dave_Wyatt> ## Assuming that malicious code does make it into Chocolatey, what's the response?  API keys revoked, packages taken offline, etc?  How fast would that happen?

