Hacker News new | ask | show | jobs
by tokyobreakfast 110 days ago
> create much more scrutiny around dependencies of 'highly scrutinised' packages like OpenSSH.

But xz is not a dependency of upstream OpenSSH you see. It was a dependency of a patch created by Linux distros for systemd integration.