

6·
9 days agoNo, they’re talking about their own dependencies


No, they’re talking about their own dependencies


Not disagreeing with you, but since the author is asking about GitHub… the XZ GitHub didn’t actually have any malicious code. Only the website tarbal did.


It’s been like this on iOS for a long time.
https://harshanu.space/en/tech/ccc-vs-gcc/ has a good overview how bad it really is