The transition of Fedora 43 to the RPM 6 package manager has been approved. Change of leadership in Fedora.

The FESCo (Fedora Engineering Steering Committee), responsible for the technical aspects of the Fedora Linux distribution development, has approved the transition to the RPM 6 package manager in the upcoming Fedora 43 release. The RPM 6.0 release is scheduled for Q3 2025.

The RPM 6 branch is notable for supporting a new format (RPM 6) that allows creating packages larger than 4 GB (overcoming this limitation is important as the SRC package for Chromium is close to this limit at 3.7 GB). The RPM 6 format utilizes 64-bit fields with larger sizes, modernized cryptographic structures, and added MIME information about files. Version RPM 5 has been skipped to avoid overlaps with the RPM5 project, which is unrelated to Red Hat's RPM and has been developed by independent developers.

Support for RPM 4 format, which uses cpio, will be fully preserved. Furthermore, the RPM 6 branch does not enforce a transition to the new package format, and distributions can choose to remain on the RPM 4 format. For example, Fedora 43 will ship with the RPM 6.0 package manager, but packages will still be in RPM 4 format for now. For those wishing to transition to the new format, the RPM 4.x branch has been updated to support reading and installing packages in RPM 6 format.

Among the significant changes in RPM 6 is the default inclusion of package authenticity checks using digital signatures. To ensure that mandatory signature verification does not complicate the installation of self-built packages, the rpmbuild utility in RPM 6 has been updated to support automatic generation of local signatures during builds. There is also an option "—nosignature" allowing forced installation of a package without signature verification.

Among other changes: the use of C++ code (C++20) is now permitted in development; multiple OpenPGP signatures can be used for each package; support for MD5, SHA1, and DSA hashes has been discontinued; support for the deprecated RPM 3 format has been ended. The capabilities of the rpmkeys utility for managing keys have been expanded, for example, the command “rpmkeys --import” can be used to update OpenPGP keys. The rpmkeys utility is now considered the primary tool for managing the key store for RPM in Fedora (the use of gpg-pubkey has been deprecated). As an alternative to GnuPG, users can now utilize the Sequoia-sq toolkit written in Rust.

Additionally, it is worth noting the appointment of a new leader for the Fedora project. Instead of Matthew Miller, who has held the position since 2014, Jef Spaleta has been appointed. He has been involved since the time when the Fedora project was not yet under the control of Red Hat. In the past, Jef served on the Fedora governance board for several years as a community representative.

The Fedora leader is an official position at Red Hat. The leader is not elected by community vote but is nominated by the previous project leader and approved by Red Hat. The development of the distribution is coordinated by a governing board consisting of 4 representatives from Red Hat and 5 from the independent developer community. The project leader is required to meet several criteria, such as a high level of expertise, experience in the community, decision-making skills, and the ability to listen to others' suggestions.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster