Summary: | Warn about insufficient package security | ||
---|---|---|---|
Product: | [Applications] Discover | Reporter: | Someone Concerned <lq1prs+2rm8s1mam7fmjxo0ka2> |
Component: | discover | Assignee: | Dan Leinir Turthra Jensen <leinir> |
Status: | CLOSED UPSTREAM | ||
Severity: | wishlist | CC: | aleixpol, nate |
Priority: | NOR | ||
Version: | unspecified | ||
Target Milestone: | --- | ||
Platform: | unspecified | ||
OS: | All | ||
Latest Commit: | Version Fixed In: | ||
Sentry Crash Report: |
Description
Someone Concerned
2020-08-04 07:33:28 UTC
Information can be sourced from we the people as described here: https://bugs.kde.org/show_bug.cgi?id=424577#c3 If all of this information is already available in the form of some kind of data stream we can subscribe to, or else it's something that Discover itself can programmatically determine, it seems reasonable to me. However I don't think KDE hosting a crowdsourced repository is an ethical plan, for the same reason I gave in Bug 424577. > I don't think KDE hosting a crowdsourced repository is an ethical plan Staying silent all while humankind plunges deeper and deeper into secular damnation with every passing day sounds even less ethical to me. We need strong information security for everyone to keep dissent and resistance possible. See: https://bugs.kde.org/show_bug.cgi?id=424577#c6 It seems like it's all coming from PackageKit, so it's there where this should be addressed. There's already ways to submit security concerns from PackageKit and they should be used with their according error messages. We can consider having the discussion over there where it will also be more exposed to the different backend developers and eventually distributions. https://github.com/PackageKit/PackageKit That said, if you consider bringing this up there, I'd recommend some more research as I don't think this is phrased in ways that can foster concord among the different actors. |