logoalt Hacker News

fsflovertoday at 3:23 PM1 replyview on HN

A distro automatically verifying that installed packages are reproducible would protect the user?


Replies

dvogeltoday at 4:49 PM

No, it wouldn't. The xzutils attacker compromised the source repository. The build pipeline portions were used to obscure the purpose of the exploit embedded in the source code repository.