I'm personally interested in three aspect of this #xz #liblzma issue which are all open questions for me at this point:
1. learn what to look for in PRs and diffs
2. how to indicate bad actors in issue trackers and mailing lists
3. who is behind this xz issue (investigative journalism and digital forensics)
I found this blog post by @[email protected] that has well documented the events regarding this recent issue which definitely worth reading:
https://boehs.org/node/everything-i-know-about-the-xz-backdoor
検索
Regarding the #xz #liblzma recent story, I believe we all (thise who care about #FLOSS) should read this well-written article:
https://robmensching.com/blog/posts/2024/03/30/a-microcosm-of-the-interactions-in-open-source-projects/