• sugar_in_your_tea@sh.itjust.works
    link
    fedilink
    arrow-up
    0
    ·
    2 days ago

    The history of Deepin code reviews clearly shows that upstream is lacking security culture, and the same classes of security issues keep appearing…

    Ouch.

    • Leaflet@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      2 days ago

      Security is hard and not the fun part of programming (for most people anyway).

      KDE and Gnome have problems too.

      Rationale for Accepting kio-admin into openSUSE

      We have dealt with these types of APIs in KDE since 2017 without achieving any notable improvements. As we are responsible for product security we tried to protect our users from potentially harmful components. At this point, though, we don’t believe that this situation will change anytime soon. Meanwhile users still want to use features like the one found in Dolphin, and don’t understand why openSUSE does not include them.

      https://security.opensuse.org/2025/02/21/kio-admin-admittance.html