[Rpm-maint] [rpm-software-management/rpm] Remove the internal OpenPGP parser (Issue #2414)
Alexander Kanavin
notifications at github.com
Sat Nov 25 07:51:25 UTC 2023
> > We can live with rpm verification disabled too.
>
> This is a terrible idea from a security perspective.
In embedded linux world, production systems are rarely if ever updated from package feeds by a package manager. Rather, the whole root filesystem gets overwritten from an image file. Package manager is used to compose that root filesystem from local packages in a controlled CI environment (where package-level security isn't needed), and to allow developers to install additional items into a running system on their desks used for development and testing (where there's no need to sign packages either).
So Yocto can accept that regression in package security, we'll make sure to place warnings where appropriate.
--
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/2414#issuecomment-1826247188
You are receiving this because you are subscribed to this thread.
Message ID: <rpm-software-management/rpm/issues/2414/1826247188 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20231124/f097cdc2/attachment.html>
More information about the Rpm-maint
mailing list