• Possibly linuxOPEnglish
    arrow-up
    19
    arrow-down
    1
    ·
    7 months ago
    link
    fedilink

    I think we need focus on zero trust when it comes to upstream software

    • jackpot
      arrow-up
      2
      arrow-down
      0
      ·
      7 months ago
      link
      fedilink

      exactly, stop depending on esoteric libraries

      • Possibly linuxOPEnglish
        arrow-up
        1
        arrow-down
        0
        ·
        7 months ago
        link
        fedilink

        It is fine to use them just know how they work and check the commit log.

        That of course requires you to pull from got instead of a tarball

        • billgamesh
          arrow-up
          1
          arrow-down
          0
          ·
          7 months ago
          link
          fedilink

          this was well hidden. not sure anyone would have spotted this by checking commit log

            • billgamesh
              arrow-up
              1
              arrow-down
              0
              ·
              7 months ago
              edit-2
              7 months ago
              link
              fedilink

              i’m not an expert, but my reading was that it was hidden in a binary used for testing EDIT: oh yeah, i see what you mean