To people looking for an archive of the XZ code, you might want to check out https://tukaani.org/xz-backdoor/ which links to https://git.tukaani.org/. GitHub is not the only source of truth, although meta information about the Pull Requests is locked in to this silo.
Conversation
Notices
-
Embed this notice
Codeberg.org (codeberg@social.anoxinon.de)'s status on Monday, 01-Apr-2024 06:38:38 JST Codeberg.org - Haelwenn /элвэн/ :triskell: likes this.
-
Embed this notice
Codeberg.org (codeberg@social.anoxinon.de)'s status on Monday, 01-Apr-2024 06:38:39 JST Codeberg.org If there was malicious code in a legitimate project hosted on #codeberg, would we remove access to it, including for security researchers?
Short: No!
We are considering how to prevent fetching malicious code by accident, though.
In any case, we are open to collaborating with security researchers. Interested? Help us build a malware hunting team: https://codeberg.org/Codeberg/Contributing/issues/44
Background: #GitHub locked access to source code of xz, which was background of active investigation from the community.
In conversation permalink Attachments
this.ven repeated this.