|
|
Log in / Subscribe / Register

A backdoor in xz

A backdoor in xz

Posted Mar 30, 2024 0:21 UTC (Sat) by jdulaney (subscriber, #83672)
In reply to: A backdoor in xz by excors
Parent article: A backdoor in xz

it almost sounds as if github should not be used as a release mechanism


to post comments

A backdoor in xz

Posted Mar 30, 2024 13:38 UTC (Sat) by smurf (subscriber, #17840) [Link]

You can use github's release mechanism all you like, just be sane about it.

This means that your tarball gets generated by a verified and pinned-down github action and doesn't access external resources. EVER.

While the fact that widely-used libraries like xz still allow developer-supplied release uploads can plausibly be explained (excused, really) with laziness, the line between that and malpractice is a thin one.

Against stupidity, the Gods themselves …


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds