• Lung
    arrow-up
    22
    arrow-down
    0
    ·
    7 months ago
    link
    fedilink

    Very generous to imagine that maintainers have so much time on their hands

    • rockSlayer
      arrow-up
      11
      arrow-down
      1
      ·
      7 months ago
      edit-2
      7 months ago
      link
      fedilink

      Bug fixes can be delayed for a security sweep. One of the quicker ways that come to mind is checking the hash between built from source and the tarball

      • Lung
        arrow-up
        14
        arrow-down
        0
        ·
        7 months ago
        link
        fedilink

        The whole point here is that the build process was infiltrated - so you’d have to remake the build system yourself to compare, and that’s not a task that can be automated