* Daniel P. Berrangé: > I see this change appears to be careful not to use to the word > "security", but preventing vendor transitions is effectively > acting as a security measure. > > If a 3rd party repo gets compromised, it purports to prevent > that repo from distributing a malicious package that "upgrades" > a standard Fedora package.
It still can use Supplements: <https://rpm.org/docs/latest/manual/dependencies.html#weak-dependencies> But perhaps it's not effective immediately? Still, vendor switching restrictions should not be advertised as a security measure. I view this more of a way to discourage certain practices, like rebuilding Fedora-provided RPMs with different build settings. Not sure if we still do this downstream with certain layered products; it used to be a constant source of headaches. Thanks, Florian -- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
