It is no theoretical argument to say that secured, multi-user workstations running F11 will upgrade into insecurity, when moving up for F12.
You must (a) be aware of the new F12 PackageKit policy and (b) remove PackageKit after upgrade to avoid this major security hole [from the PoV of a multi-user admin].
How many classrooms, laptops, workstations will even be aware of this, given that this is not mentioned in F12-gold release notes at all?