* Daniel P. Berrangé:

> I see this change appears to be careful not to use to the word
> "security", but preventing vendor transitions is effectively
> acting as a security measure.
>
> If a 3rd party repo gets compromised, it purports to prevent
> that repo from distributing a malicious package  that "upgrades"
> a standard Fedora package.

It still can use Supplements:

<https://rpm.org/docs/latest/manual/dependencies.html#weak-dependencies>

But perhaps it's not effective immediately?  Still, vendor switching
restrictions should not be advertised as a security measure.

I view this more of a way to discourage certain practices, like
rebuilding Fedora-provided RPMs with different build settings.  Not sure
if we still do this downstream with certain layered products; it used to
be a constant source of headaches.

Thanks,
Florian

-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to