devsetup1-8 Exercise 1: Add Microsoft's Repository and Install VS Code ======================================================================= STEP 1: CHECK FIRST ------------------- command -v code # nothing on a fresh install apt policy code # no candidate: Debian does not carry VS Code STEP 2: GET AND INSPECT THE KEY ------------------------------- sudo apt install wget gpg wget -qO- https://packages.microsoft.com/keys/microsoft.asc | sudo gpg --dearmor -o /usr/share/keyrings/microsoft.gpg gpg --show-keys /usr/share/keyrings/microsoft.gpg The last command prints the key's owner (Microsoft) and its fingerprint. Compare the fingerprint with the one Microsoft publishes before relying on it. STEP 3: ADD THE REPOSITORY -------------------------- Create /etc/apt/sources.list.d/vscode.sources (for example with sudo nano /etc/apt/sources.list.d/vscode.sources): Types: deb URIs: https://packages.microsoft.com/repos/code Suites: stable Components: main Architectures: amd64,arm64,armhf Signed-By: /usr/share/keyrings/microsoft.gpg STEP 4: INSTALL AND PROVE WHERE IT CAME FROM -------------------------------------------- sudo apt update sudo apt install code apt policy code # the version table shows packages.microsoft.com code --version type -a code # one copy, /usr/bin/code dpkg -S "$(readlink -f "$(command -v code)")" # names the "code" package as the owner # (readlink -f follows a symlink to the real file) WHAT Signed-By DOES, AND WHAT YOU TRUSTED ----------------------------------------- Signed-By tells apt that packages from this repository must be signed by this one key, and that the key is trusted for this repository only. Microsoft's key cannot vouch for packages from Debian or from any other source. You have still trusted Microsoft to supply and update software that runs with your user's permissions, on every apt upgrade from now on. That is a decision to make on purpose, and the reason to keep third-party repositories to the ones you actually need. WHY THIS WORKS AS AN ANSWER --------------------------- Each step is checked, not assumed: the key is inspected before use, and the origin of the installed package is confirmed with apt policy and dpkg -S. It also leaves behind a single file, vscode.sources, which is what Chapter 10 puts in the rebuild script.