4 ms·
They likely put a program on the build server to make the changes after checkout before build. Which would be impossible to detect.
by codenesium 6y ago
They likely put a program on the build server to make the changes after checkout before build. Which would be impossible to detect.
- raverbashing 6y ago"impossible to detect" except for all the merge conflicts and build breaking changes, etc
- vsareto 6y agoHuh? After the build server checks out the code, write malicious code to the source files directly just before the compilation step. No merge conflicts or breaking changes unless the added code failed to compile. It's reasonable to guess they had access to the source from the build server, so they could reproduce this environment themselves and test on their own.