openSUSE Removes Deepin Desktop Over Security Policy Violations

'In recent development, the openSUSE project has decided to remove the Deepin Desktop Environment (DDE), well-known for its polished visuals and user-friendly experience, from its repositories, citing substantial packaging policy violations. According to disclosures from the openSUSE security team, a troubling workaround was discovered in the DDE packaging. Specifically, the Deepin community packager introduced a “license agreement” dialog within the deepin-feature-enable package, effectively circumventing standard security review processes required by openSUSE. Ordinarily, components such as D-Bus system service configurations and Polkit policies must undergo stringent review by the SUSE security team before being whitelisted for inclusion in openSUSE distributions. In this case, however, the discovered “license agreement” allowed users to bypass these security checks, installing components flagged by the security team as potentially unsafe simply by accepting the license.' -- source: https://linuxiac.com/opensuse-removes-deepin-desktop-over-security-policy-vi... Cheers, Peter
participants (1)
-
Peter Reutemann