Hacker News new | ask | show | jobs
by IshKebab 248 days ago
That's really incidental. There are a gazillion vectors for exploitation once you control a package like xz. You can't fix this issue by plugging them one by one.