4 ms·
The binaries get signed with signify by god knows who. But other than that. Everything goes through unsigned patches via mail. Peers have to reply with "ok". So
by noAnswer 2y ago
The binaries get signed with signify by god knows who. But other than that. Everything goes through unsigned patches via mail. Peers have to reply with "ok". Someone with write access to the CVS has to check it in. How is this process more safe against an xz style social engineering attack?
On top of that, would a direct attack on their CVS even be noticed? I hope so.