top | item 39911824

(no title)

ajoberstar | 1 year ago

That's not what happened. Downstream was building from source, that source just had malicious code in it.

One part was binary, the test file (pretty common), but checked into the repo. One part was in the build config/script, but was in the source tarball and not in the repo.

discuss

order

No comments yet.