[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: xz backdoor



On Sun, Mar 31, 2024 at 12:13:30PM +0200, Alexandre Detiste wrote:
> Le dim. 31 mars 2024 à 10:17, Sirius <sirius@trudheim.com> a écrit :
> > Reduction of complexity is IMHO always worthwhile as it would open the
> > door for more people being able to step up as maintainers (taking into
> > account that volunteers right this minute might not be overly welcome and
> > when they are, they should likely not be near authentication, crypto and
> > compression at least initially).
> 
> It's worse than that: to make the xz MR looks more legit;
> the fake puppet profile "Hans Jansen" also sent _maybe_ legit MR to
> random games repos:
>    https://news.ycombinator.com/item?id=39868390
> 
> Here fixing our Salsa tooling could help also making real newcomers
> life more enjoyable by always disabling MR again upstream & pristine-tar tar.
Yeah, those MRs never made sense to time, it's obvious that "run gbp
import-orig and propose the result as MRs" is just not a workflow we
support with the existing tools.

-- 
WBR, wRAR

Attachment: signature.asc
Description: PGP signature


Reply to: