Fedora has retired all Deepin Desktop Environment (DDE) packages from its official repositories after concluding that long-running security concerns and poor maintainer engagement were not resolved. Fedora said the packages had been in poor condition for an extended period and that efforts to re-establish effective maintenance failed, even after maintainers were given a final four-week window to respond. The distribution said Deepin could return only after undergoing a fresh security review.
The move follows SUSE/openSUSE dropping Deepin packages over similar concerns, including an alleged packaging policy violation that bypassed normal RPM security review requirements to install restricted assets. Scrutiny of Deepin has persisted since a 2018 controversy in which the Deepin Store sent unencrypted requests to CNZZ containing browser-agent and other user information; although that telemetry issue was reportedly fixed and later reviews found no active spyware in Deepin's core, trust in the project continued to erode. Deepin packages are now absent from the official Fedora and SUSE repositories pending stronger review and remediation.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Fedora decided to retire all Deepin packages after its own review found poor package condition, unresolved security concerns, and failed attempts to re-establish effective maintainer engagement. Fedora said Deepin could return only after passing a fresh security review.
Before retiring the packages, Fedora gave Deepin maintainers a final four-week period to engage and improve the security and maintenance situation. Fedora later concluded that key maintainers did not adequately respond.
Matthias Gerstner reported that dde-file-manager-daemon exposed dangerous privileged functionality over D-Bus without proper polkit protection, allowing any user to potentially hijack the service and access sensitive data including cleartext Samba passwords. The audit also found insecure world-readable logging and multiple unsafe methods affecting user, group, Samba, tagging, and filesystem operations, concluding the package was not acceptable for openSUSE in its current form.
In May 2025, SUSE removed Deepin packages from openSUSE after identifying a packaging policy violation that bypassed normal RPM security review requirements to install restricted assets. The decision was tied to broader security concerns around Deepin packaging practices.
In 2018, Deepin faced scrutiny after the Deepin Store was found sending unencrypted requests to CNZZ that included browser agent and other user information. Deepin reportedly later addressed the telemetry issue.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
zdnet.fr
Open sourcezdnet.com
Open sourcexda-developers.com
Open sourcebugzilla.suse.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.