Mailinglist Archive: opensuse-buildservice (311 mails)

< Previous Next >
Re: [opensuse-buildservice] Unique vendors per repository are a must and the current setup is a timebomb / security hole
  • From: "Hans-Peter Jansen" <hpj@xxxxxxxxx>
  • Date: Thu, 26 Nov 2009 20:22:50 +0100
  • Message-id: <200911262022.50669.hpj@xxxxxxxxx>
On Thursday 26 November 2009, 18:37:46 Michael Schroeder wrote:
On Thu, Nov 26, 2009 at 06:06:47PM +0100, Hans-Peter Jansen wrote:
On Thursday 26 November 2009, 17:21:53 Michael Schroeder wrote:
On Thu, Nov 26, 2009 at 11:05:00AM +0100, Stephan Kleine wrote:
Now please ask around how many people would consider it naturally
if their package manager switches from one repo to the other
without them being unable to prevent this.

AFAIK zypp is the only software manager that looks at the vendor to
prevent repo switching. All other managers smart, yum, apt...) only
have repo priorities.

but yum provides exclude patterns, which I do miss from time to time.

Just curious: how are they different from locks?

Hrmpf. Apart from the fact, that yum is missing an UI, they pretty much
resemble the same functionality ;-). Thanks for bringing this to my
attention - I didn't notice before, silly me.

Thanks,
Pete

--
To unsubscribe, e-mail: opensuse-buildservice+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse-buildservice+help@xxxxxxxxxxxx

< Previous Next >