On Fri, May 22, 2020 at 12:53:03PM -0700, Brian Dolbec wrote: > We cannot exclude overlays which will have cat/pkg not in the main > gentoo repo. So, we should not excludea submission that includes a few > of these.
To avoid this problem, even if imperfectly, it should be possible to track what repository a given package is installed from and then check its validity based on a list of valid packages for a given overlay.
signature.asc
Description: PGP signature