OpenMandriva Says Former Contributor Sabotaged Its Repositories

Lobsters Hottest News

Summary

OpenMandriva released a statement accusing former contributor Davide Beatrici of sabotaging its GitHub repositories and publishing empty packages in its Cooker development branch, potentially harming systems with GNOME and COSMIC desktops. The project is restoring data and has declined to pursue legal action.

<p><a href="https://lobste.rs/s/q5vga3/openmandriva_says_former_contributor">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 07/09/26, 07:42 AM

# OpenMandriva Says Former Contributor Sabotaged Its Repositories Source: [https://linuxiac.com/openmandriva-says-former-contributor-sabotaged-its-repositories/](https://linuxiac.com/openmandriva-says-former-contributor-sabotaged-its-repositories/) OpenMandriva, one of the successors to the legendary Mandrake Linux, has published a public statement warning its community about what it describes as an attempted sabotage of the Linux distribution following an internal dispute among contributors\. The project says the incident began after several team disruptions involving contributor behavior, private messages, and access to OpenMandriva’s infrastructure\. According to the statement, Davide Beatrici, who is known for his work on the Mumble project, joined OpenMandriva some time ago and later offered to move or mirror several of the distribution’s repositories to his private OneDev instance\. However, OpenMandriva says some team members were not comfortable with this setup\. They preferred to keep the project’s infrastructure on a public platform like GitHub instead of letting one person control important repositories\. The situation reportedly got worse after another contributor was removed from one of OpenMandriva’s Matrix chats for what the project describes as abusive behavior toward users and team members\. OpenMandriva says this caused two people to leave the project, including Beatrici\. After that, the project started to cut ties with the private infrastructure mirror\. OpenMandriva claims this led to the sabotage attempt\. In its statement, the project says Beatrici used his remaining administrative privileges to delete part of OpenMandriva’s GitHub repository work, including material that had been kept for years\. More seriously for users, an empty package was also published in the Cooker repository, which replaced all GNOME and COSMIC packages\. This could have harmed systems running those desktop environments, especially since Cooker is OpenMandriva’s rolling development branch\. Users there expect faster updates and accept more risk than on stable releases\. The project says it is now restoring the deleted repositories and fixing the affected packages\. Additionally, the distro conducted a full system audit and found no other problems aside from the removed packages\. Although OpenMandriva called the actions unacceptable and said it could have taken legal action, the project has decided not to do so\. So, what is the conclusion of all this? Above all, trust is important, but so is proper access control\. As you know, community projects often rely entirely on volunteers, but giving too much control to a few people can be risky when disputes happen\. Currently, the project is working to restore the affected repositories and packages\. For additional details,[see OpenMandriva’s statement](https://forum.openmandriva.org/t/statement-regarding-attempted-distribution-sabotage/8997)\.

Similar Articles

Dozens of Red Hat packages backdoored through its official NPM channel

Ars Technica

Dozens of Red Hat packages were backdoored through the company's official NPM channel using the Shai-Hulud worm, which compromised Red Hat's CI/CD pipeline via GitHub Actions OIDC. Red Hat has removed the malicious packages and stated they were internal only, but the attack underscores escalating supply-chain risks.

Bambu Lab is abusing the open source social contract

Hacker News Top

Bambu Lab threatened legal action against a developer who forked OrcaSlicer to bypass its cloud dependency, escalating a long-standing dispute over the open source social contract and user control over purchased hardware.

Anonymous GitHub account mass-dropping undisclosed 0-days

Hacker News Top

An anonymous GitHub account has released a large collection of proof-of-concept exploits for undisclosed 0-day vulnerabilities in numerous popular software packages, including 7zip, Docker, Firefox, FFmpeg, Ghidra, libssh2, Nmap, PHP, and VLC.