Why Nostr? What is Njump?
2024-04-01 18:02:34

Ariadne Conill 🐰:therian: on Nostr: it should be noted that arch linux's reproducible source tarballs project actually ...

it should be noted that arch linux's reproducible source tarballs project actually caught the #xzbackdoor when they went and looked at it: https://gitlab.archlinux.org/archlinux/packaging/packages/xz/-/commit/881385757

while not perfect, this is a practical defense against backdoored source tarball releases.
Author Public Key
npub1lxcygzft450wuzz3kh9xg7vnm25fsd668wgse0u334r65n8u9yksqzhll9