risible lack of detail. if there were something there there, it would be front and center https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/
PSA: HEADS UP EVERYONE! Another project noticed they were being targeted with similar social engineering tactics as the xz-utils backdoor attack. Be on the lookout for random people demanding that you add someone new as a maintainer for vague but urgent "reasons". Google their emails, check their GitHub/GitLab histories, see if they are on Mastodon/Reddit/"X"/LinkedIn. If they do not have an internet footprint, they are probably a plant.
https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/
#opensource #opensourcesecurity
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.