Security considerations while downloading packages from CRAN

48 views
Skip to first unread message

Dhruv Sakalley

unread,
Apr 7, 2016, 12:21:03 PM4/7/16
to Microsoft R Open / Revolution R Open
Hi,

I understand now you can use R services and packages can now be downloaded into the same ecosystem as SQL Server 2016. What are the security considerations for such an environment? How safe are the packages on MRO CRAN and what kind of security reviews are done prior to making these packages generally available?

Regards,
Dhruv

adev...@microsoft.com

unread,
Apr 8, 2016, 9:51:30 AM4/8/16
to Microsoft R Open / Revolution R Open
Hi, Dhruv

You are correct that it is possible to install CRAN packages on a SQL Server 2016 instance with R Server. However, it is up the the system administrator to ensure that any third party packages comply with internal security policy. In other words, Microsoft can not make any statements about how a third party package will behave on any machine.

For this reason, only the system administrator of a SQL machine can install new packages.

I am sorry, but I can't be more specific than this.

Regards

Andrie

adev...@microsoft.com

unread,
Apr 8, 2016, 4:25:54 PM4/8/16
to Microsoft R Open / Revolution R Open
Since posting my reply, I have learnt that there are in fact additional security features implemented in SQL-Server 2016 R Services.

I'm trying to find the canonical information and will link to it once I have the link.

Andrie

On Thursday, April 7, 2016 at 5:21:03 PM UTC+1, Dhruv Sakalley wrote:
Reply all
Reply to author
Forward
0 new messages