Hey Richard,

> Should we have a higher level of attention to these packages?  We
> already have "critical path", but that's a broad category now.  These
> seem like they are "security path" packages, an intentionally small
> subset associated with very secure services which are enabled by
> default.

It sounds like a good plan to put certain dependencies on a critical path. 
Perhaps
anything that is used by packages included in the various editions of Fedora 
that
allow for remote access (even if disabled by default) could fall under that 
path?

We could also try to ensure that packages do not contain any binary blobs and 
instead
require generation scripts for those that we can run ourselves.

Regards,

Simon
--
_______________________________________________
devel mailing list -- devel@lists.fedoraproject.org
To unsubscribe send an email to devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to