[Rpm-maint] [rpm-software-management/rpm] Remove the internal OpenPGP parser (Issue #2414)

Demi Marie Obenour notifications at github.com
Sat Nov 25 23:30:31 UTC 2023


> > > We can live with rpm verification disabled too.
> > 
> > 
> > This is a terrible idea from a security perspective.
> 
> In embedded linux world, production systems are rarely if ever updated from package feeds by a package manager. Rather, the whole root filesystem gets overwritten from an image file. Package manager is used to compose that root filesystem from local packages in a controlled CI environment (where package-level security isn't needed), and to allow developers to install additional items into a running system on their desks used for development and testing (where there's no need to sign packages either).
> 
> So Yocto can accept that regression in package security, we'll make sure to place warnings where appropriate.

Another option would be to use the host system’s RPM for verifying the packages.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/2414#issuecomment-1826442158
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/issues/2414/1826442158 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20231125/f266cf2e/attachment.html>


More information about the Rpm-maint mailing list