KDE6 release: D-Bus and Polkit Galore (SUSE security team blog)
The SUSE Security Team Blog is carrying adetailed article on SUSE's review of the KDE6 release.
The SUSE security team restricts the installation of system wideD-Bus services and Polkit policies in openSUSE distributions andderived SUSE products. Any package that ships these features needsto be reviewed by us first, before it can be added to productionrepositories.In November, openSUSE KDE packagers approached us with a long listof KDE components for an upcoming KDE6 major release. The packagesneeded adjusted D-Bus and Polkit whitelistings due to renamedinterfaces or other breaking changes. Looking into this manycomponents at once was a unique experience that also led to newinsights, which will be discussed in this article.