I’ve received a few pings/questions regarding my involvement in the xz stuff. I’ve posted a statement on the original PR. https://github.com/jamespfennell/xz/pull/2#issuecomment-2027836356

Kudos to people who managed to find me here despite me not using my real name on this 

feat: update vendored xz to 5.6.1 by jaredallard · Pull Request #2 · jamespfennell/xz

Updates the vendored version of xz to be 5.6.1. Also updates the vendor script to support the addition of SPDX-License-Identifier headers into some files.

GitHub
A Dependency Upgrade

The views expressed here in this post are not representative of my employer, 1Password except where explicitly called out. Last week, I made a PR to an open-source repository. It was a seemingly innocuous change. One that only upgraded a submodule in the repository to ensure the underlying C code

Jared Allard
@dwari how's things?
@mikoto better now that I got to actually reply 🤣
@dwari it is scary what some people can do tbh
@ezio @dwari reminds me I should do more to improve my opsec, bit too lazy tho
@dwari I saw you getting mentioned on Twitter and thought "that's my friend" and came here to poke you
@mira @dwari Makes me worried about my privacy. On the other hand I do not exactly try hiding my pseudonyms.