• SuperIce@lemmy.world
      link
      fedilink
      English
      arrow-up
      20
      ·
      7 months ago

      Yeah, it looks like that little Jenga block from the xkcd meme was XZ and a bunch of infrastructure is gonna have issues because of it.

    • Brunacho@scribe.disroot.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      7 months ago

      Gonna take a bit. The dudes been doing the releases for over a year, everything they touched is suspect now even if nothing earlier is known. Also some other associated accounts have been doing shady stuff too.

      gonna take even a bit more now. Github closed the account and project making it really difficult to see their commits and merges and analyze them.