Open source developers are not a supply chain. We need to stop calling Jia Tan's intentionally malicious activities a "supply chain attack".

#xz #cve20243094