Y
Hacker News
new
|
ask
|
show
|
jobs
by
charcircuit
1 day ago
There are subtle things like abusing how github handles forks which can make malicious PKGBUILD a matter of just changing the rev with no hint in the file itself.
1 comments
thayne
1 day ago
Perhaps, but it would be pretty unusual to use a commit/hash id instead of a version tag, or the main development branch.
link