Hacker News new | ask | show | jobs
by solarkraft 810 days ago
> "But I want and can maintain it, can I take it over?" Let me put it plain and simple: No! I don't know you, I don't trust you! Fork it and carry on!

They learned a good lesson from the liblzma situation.

1 comments

Maybe. ‘Fork it’ means a bad actor can… fork it and advertise as a successor.
Then it's up to the consumer to judge that themselves. One component of the liblzma backdoor was that distros were already linking to those tarballs. That wouldn't happen here as the repo will essentially freeze.
Better than the alternative