Fedora decided to remove Deepin desktop packages after ongoing security concerns and weak maintenance—mirroring openSUSE’s earlier removal triggered by packaging policy violations, unresolved D‑Bus and privilege‑relat... openSUSE first removed Deepin after discovering a workaround that bypassed required security rev...

Create a landscape editorial hero image for this Studio Global article: Why did Fedora decide to remove the Deepin desktop environment from its repositories, how is this decision related to openSUSE’s earlier rem. Article summary: Fedora decided to remove Deepin desktop packages because of continuing security concerns and weak package maintenance, and that decision closely follows openSUSE’s earlier removal of Deepin for similar reasons.[4][6] The. Topic tags: general, general web, user generated, documentation. Reference image context from search candidates: Reference image 1: visual subject "# openSUSE: Deepin Desktop Removal - Security Risks and Protocols. Alright—it’s not just about pulling a desktop environment from the repositories; it’s about what happens behind t" source context "openSUSE Discontinues Deepin Desktop Because of Security Concerns" Reference image 2: visual subject
Fedora and openSUSE—two major community Linux distributions—recently decided to remove the Deepin Desktop Environment (DDE) from their repositories. While the timing differs, the underlying reasons are closely related: unresolved security concerns, packaging policy violations, and difficulties maintaining the software at the security standards expected by these distributions.
Together, the decisions illustrate how Linux distributions weigh usability and aesthetics against the need for transparent code review, secure packaging practices, and responsive upstream maintenance.
The Fedora Engineering Steering Committee (FESCo), which oversees technical policy and packaging decisions in Fedora, decided to retire and remove Deepin desktop packages from the distribution.
Two main issues drove the decision:
During the review process, Fedora developers also reported difficulty contacting some of the package maintainers responsible for Deepin components. For a community distribution, this matters: timely maintainer responses are essential for fixing vulnerabilities, responding to security reports, and ensuring long‑term stability.
Because of these risks, Fedora concluded that continuing to ship the desktop environment would not meet its standards for maintenance and security.
Fedora’s move did not happen in isolation. openSUSE had already removed Deepin from its repositories earlier, citing security policy violations and a history of difficult code reviews.
The openSUSE security team reported that a community packager implemented a workaround to bypass the project’s standard RPM packaging mechanisms. This workaround allowed restricted assets to be installed without triggering the normal security review process.
This bypass was considered a serious policy violation because openSUSE relies on strict packaging rules to ensure that components interacting with sensitive system functionality undergo mandatory security checks.
Once that violation was discovered, the project removed Deepin packages from its distributions until the issues could be resolved.
Fedora developers evaluating their own Deepin packages were therefore already aware of the concerns raised by openSUSE.
Beyond packaging policy violations, several technical security concerns were repeatedly raised during reviews of Deepin components.
Reports highlighted issues involving D‑Bus services and privilege escalation paths, particularly where Deepin components interact with system services. Some reporting also referenced problems related to Polkit (PolicyKit) privilege handling, which controls how user processes request administrative permissions.
One area of long‑running concern was the Deepin file manager’s D‑Bus service, whose security review had been ongoing for years without reaching a stable resolution. Reviewers noted that fixes sometimes addressed reported problems only partially or introduced new issues in subsequent updates.
Because D‑Bus services can expose system functionality to applications, design mistakes or insufficient restrictions could allow unintended privilege access if not carefully audited.
Another factor influencing both distributions was communication and responsiveness from upstream developers.
During earlier security reviews, openSUSE maintainers reported difficulties getting issues fully addressed and noted that fixes sometimes did not fully resolve the underlying problems.
For Linux distributions, upstream collaboration is critical. When maintainers cannot reliably coordinate with upstream developers, it becomes harder to:
Combined with the packaging violation and unresolved technical concerns, this lack of effective coordination contributed to the decision to remove Deepin from official repositories.
The removal from Fedora and openSUSE repositories does not mean Deepin itself has disappeared. It simply means those distributions no longer ship or maintain the packages in their official repositories.
Users who prefer Deepin still have several options:
However, using unofficial packages comes with trade‑offs. Packages outside official repositories may not undergo the same level of security auditing or packaging policy checks required by distributions like Fedora or openSUSE.
The Deepin removal highlights an important reality of Linux distribution governance: inclusion depends not only on features or popularity but also on maintainability, transparency, and security review compliance.
Even visually polished or widely used desktop environments can be removed if maintainers cannot ensure secure integration with the underlying system.
For Fedora and openSUSE, the decision ultimately reflects a conservative security stance—prioritizing trustworthy packaging and responsive maintenance over keeping every desktop environment available in the official repositories.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
Fedora decided to remove Deepin desktop packages after ongoing security concerns and weak maintenance—mirroring openSUSE’s earlier removal triggered by packaging policy violations, unresolved D‑Bus and privilege‑relat...
Fedora decided to remove Deepin desktop packages after ongoing security concerns and weak maintenance—mirroring openSUSE’s earlier removal triggered by packaging policy violations, unresolved D‑Bus and privilege‑relat... openSUSE first removed Deepin after discovering a workaround that bypassed required security reviews for restricted components, raising trust and policy‑compliance issues.[1][14]
Users who still want Deepin can run distributions that officially support it or install unofficial packages, but these may not receive the same security review as packages in Fedora or openSUSE repositories.