@wingo OpenSSF and Linux Foundation want to grab supply chain security money from the US federal government; the xz backdoor is an opportunity for them to demonstrate that “something needs to be done” and that they’re well positioned to “do something”.