In Fedora, it was decided to remove packages with the Deepin desktop environment.

The FESCo (Fedora Engineering Steering Committee), responsible for the technical development of Fedora Linux, has decided to remove packages related to the Deepin desktop environment from the Rawhide repository due to maintenance issues. The team responsible for Fedora releases has been instructed not to restore these packages if a request comes from the deepinde-sig group without a re-evaluation process. The autumn release of Fedora Linux 45 will be without support for Deepin.

The reason for the removal was the lack of activity in the deepinde-sig maintenance group and the abandoned nature of the packages, which had remained unaddressed for a long time with serious bugs and presumably unresolved vulnerabilities. Some of the unaddressed bugs caused build issues from source (FTBFS) or installation failures (FTI).

A month ago, FESCo members decided to postpone the removal of the packages and attempted to contact the maintainers of Deepin packages for updates on the project's status. The developers managed to reach the main maintainer, who explained that he had no objection to the removal of the packages from the repository, as all members of the deepinde-sig group are too busy with their primary work and do not have time to continue maintaining the Deepin packages for Fedora, and efforts to recruit new maintainers have not been successful.

A year ago, packages with Deepin were removed from the openSUSE repositories because the maintainer of Deepin attempted to bypass the established openSUSE package review rules. Without notifying the security team, they placed the package 'deepin-feature-enable' in the repository, which installed additional components that had not been reviewed and contained unresolved security issues. If the user confirmed the operation, files were extracted into system directories, bypassing the standard mechanisms for installing system components, including additional D-Bus configuration files and Polkit policies from tar archives included in the deepin-daemon-dbus and deepin-daemon-polkit packages. Similar manipulations were not carried out in the Fedora packages, but there were no mandatory security review requirements for D-Bus services and Polkit policies (some Deepin components had not passed review with the SUSE Security Team, and the maintainer in openSUSE organized their installation through a loophole).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster