They also have a rather informal release process. Their "release notes" are just a very long NEWS file[2] in the git repo, with notes of trivial and critical changes mishmashed together. And for some reason, to this date there is not a mention of the DHCP remote exec vuln fixed in the latest release.
I must say I don't feel too good about this project's attitude towards security. Compare this to e.g. Apache.
[1] https://www.theregister.co.uk/2018/10/26/systemd_dhcpv6_rce/
You are comparing apples and oranges.
systemd replaces several components you would typically find as core components (multiple packages) which everything in a distro is built and depend upon, init-scripts being no exception.
Or at least it does if you present the criticism that systemd is too big.
Make up your mind: either systemd is not such a big monolith or it does in fact make sense to compare it to a minimal Linux distro.
You can’t have it both ways.
2) Every "core component" in any system, "minimal" or otherwise, will indeed have had more security review than the systemd code base.
3) Pid 1 - Sponsored by NSA and DoD vis a vis Redhat defense contracts.
If I extend the search to all packages built from the "sysvinit" source (which includes packages like initscripts and sysvinit-utils), the count increases to 8. (source: https://www.debian.org/Bugs. I'm not linking to exact queries since they take quite some time and HN has a tendency of taking down Debian's bug tracker)
That's literally the definition of replacement.
So you're correct, in a way.
Are you saying you can trivially audit those?
Not fully, no but as far as I can tell, it has overlapping responsibilities.
My main thought when mentioning it, was automatic restart of services in the case of failure.
I can't think of a single init system which has been audited.
Lol. I'm sure you're the only person on earth who can think of all the corner conditions when reading a bash script.
Auditing a shell script for security is near impossible to do.
And all the source code for bash and all the other tools the init-scripts invokes?
And I can read systemd unit files. That doesn't tell me anything about the security of the system in charge of running them.
https://www.cvedetails.com/product/21050/GNU-Bash.html?vendo...