@wingo OpenSSF and Linux Foundation want to grab supply chain security money from the US federal government; the xz backdoor is an opportunity for them to demonstrate that “something needs to be done” and that they’re well positioned to “do something”.
Conversation
Notices
-
Embed this notice
Ludovic Courtès (civodul@toot.aquilenet.fr)'s status on Tuesday, 16-Apr-2024 22:14:39 JST Ludovic Courtès - Haelwenn /элвэн/ :triskell: likes this.
-
Embed this notice
Andy Wingo (wingo@mastodon.social)'s status on Tuesday, 16-Apr-2024 22:14:40 JST Andy Wingo risible lack of detail. if there were something there there, it would be front and center https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/