GeistHaus
log in · sign up

How NixOS and reproducible builds could have detected the xz backdoor for the benefit of all

luj.fr

Introduction In March 2024, a backdoor was discovered in xz, a (de)-compression software that is regularly used at the core of Linux distributions to unpack...

1 page links to this URL
Could the XZ backdoor have been detected with better Git and Debian packaging practices?

The discovery of a backdoor in XZ Utils in the spring of 2024 shocked the open source community, raising critical questions about software supply chain security. This post explores whether better Debian packaging practices could have detected this threat, offering a guide to auditing packages and suggesting future improvements.\n

1 inbound link article en Post [Debiansecuritysupply chain securityopen sourcegit]