Package: dpkg Version: 1.19.7 Severity: wishlist Usertags: audit Hi,
It would be nice if dpkg was logging audit events when packages are installed/updated/removed/... The type of the message is AUDIT_SOFTWARE_UPDATE, the content is not documented, AFAICS, the messages look something like: op=install sw="ntpdate-4.2.6p5-25.el7_3.2.x86_64" sw_type=rpm key_enforce=0 gpg_res=0 root_dir="/" rpm is already doing that, and the code is available at https://github.com/rpm-software-management/rpm/blob/master/plugins/audit.c Kind regards, Laurent Bigonville -- Package-specific info: System tainted due to merged-usr-via-symlinks. -- System Information: Debian Release: bullseye/sid APT prefers unstable-debug APT policy: (500, 'unstable-debug'), (500, 'unstable'), (1, 'experimental-debug'), (1, 'experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 4.19.0-5-amd64 (SMP w/8 CPU cores) Kernel taint flags: TAINT_FIRMWARE_WORKAROUND Locale: LANG=fr_BE.UTF-8, LC_CTYPE=fr_BE.UTF-8 (charmap=UTF-8), LANGUAGE=fr_BE.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: SELinux: enabled - Mode: Permissive - Policy name: refpolicy Versions of packages dpkg depends on: ii libbz2-1.0 1.0.6-9.1 ii libc6 2.28-10 ii liblzma5 5.2.4-1 ii libselinux1 2.9-2 ii tar 1.30+dfsg-6 ii zlib1g 1:1.2.11.dfsg-1 dpkg recommends no packages. Versions of packages dpkg suggests: ii apt 1.8.2 pn debsig-verify <none> -- no debconf information