|
|
|
|
|
by benregenspan
38 days ago
|
|
Is the "Jia Tan" XZ Utils compromise not a good example? That relied on code snuck into a release that was not in source. (It was caught before being promoted into a stable Debian release, yes, but this sort of relied on a happy accident, too close for comfort) |
|
Still, lots of good non-security benefits to reproducible builds too.