I don’t agree with all the doom saying about XZ incident.

You just know orgs are going to return after Easter and panic about it unnecessarily (they’re likely still on Redhat 6). It doesn’t impact them as it was caught super early.

Regarding the narrative that there’s nothing that can be done about these type of attacks - I also don’t agree. There’s already a change in the pipeline to systemd which would have prevented it.

The thing needs rational, calm reaction and response.

@GossiTheDog it's almost impossible to prevent these kind of attacks. The OSS philosophy promotes (as it should) collaboration so there is always the possibility of malicious contributions. We can and should mitigate this, wtih the mechanics that are already in place and we can handle it just as we handle bugs, with segregated realms of stability.