Preupgrade

Björn Persson bjorn at xn--rombobjrn-67a.se
Thu Nov 13 00:24:19 UTC 2008


Rahul Sundaram wrote:
> Björn Persson wrote:
> > Preupgrade is a good idea. Too bad its authors give security such a low
> > priority. Personally I won't use Preupgrade until it verifies
> > cryptographic signatures on everything it downloads.
>
> It uses yum which should handle that. You should file a RFE if you are
> talking about something different.

Implementing these would be a start:

https://fedorahosted.org/preupgrade/ticket/7
https://fedorahosted.org/preupgrade/ticket/8

When I see those tickets closed I'll review Preupgade again to see if there's 
more to do to make it secure.

Björn Persson
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part.
URL: <http://listman.redhat.com/archives/fedora-list/attachments/20081113/078f29d3/attachment-0001.sig>


More information about the fedora-list mailing list