[BlueOnyx:23808] Re: Harmful (?) repos being activated

Michael Stauber mstauber at blueonyx.it
Tue Apr 28 23:04:20 -05 2020


Hi Maurice,

> A little warning, perhaps Michael can comment.
> 
> After a recent yum update, two repos are automatically being activated
> (seen on 5210R). I believe these repos might harm BlueOnyx.
> These are:
> /etc/yum.repos.d/epel.repo.rpmnew
> /etc/yum.repos.d/epel-modular.repo

I just checked.

On itself the "epel-repo" RPM doesn't get installed. You really have to
install that one manually.

Once it *is* installed: As long as the RPM is listed in the RPM
database, it'll get updated via YUM/DNF whenever there is an update
published for it.

I do have some devel boxes that have Epel installed, but I had edited
/etc/yum.repos.d/epel.repo to set "enabled=0".

Now it looks like "epel-release" recently got updated and of course then
everyone who had the RPM installed gets the updated version. If you had
deleted the epel repos from /etc/yum.repos.d/, then the update would
have brought them back. If you instead edited the configs and had set
"enabled=0", then the update would have installed the new configs as
*.rpmnew and wouldn't have activated the repos again.

Also: Be careful with the Remi repo. That one has a requirement for the
Epel repo, in which case you get both installed and activated.

-- 
With best regards

Michael Stauber



More information about the Blueonyx mailing list