Hacker News new | ask | show | jobs
by DistractionRect 1188 days ago
They specifically called out the need to review all code that ever interacted with github. The implication is that you can't trust it hasn't been tampered with.