Hacker News new | ask | show | jobs
by charcircuit 1 day ago
There are subtle things like abusing how github handles forks which can make malicious PKGBUILD a matter of just changing the rev with no hint in the file itself.
1 comments

Perhaps, but it would be pretty unusual to use a commit/hash id instead of a version tag, or the main development branch.