3 ms·
This is an "in addition to" problem though, not an "instead of" problem. Having code reviewed the PKGBUILD doesn't mean the upstream software is safe to use, h
by kpcyrd 4mo ago
This is an "in addition to" problem though, not an "instead of" problem.
Having code reviewed the PKGBUILD doesn't mean the upstream software is safe to use, having reviewed the upstream software and it's dependency tree doesn't mean the PKGBUILD is safe to use.
- dsp_person 4mo agoAlso have realized at some point that reviewing the PKGBUILD and code in github repo still doesn't check whether the github release files are compromised.
- backscratches 4mo agoBuild it yourself or bust
- deleted 4mo ago[deleted]
- deleted 4mo ago[deleted]