Guy has Go project that wraps xz to provide native Go bindings. Project has had no commits for THREE YEARS.
Suddenly some guy sends a PR to update the version of xz in use to the backdoored version:
https://github.com/jamespfennell/xz/pull/2
Then you got some guy in the HN comments astroturfing everyone claiming that he knows the guy who submitted the PR IRL and he's a "cool dude", or something.
All this shit is so sus.
CAN THE FUCKING FEDS PLEASE STOP BACKDOORING OPEN SOURCE SOFTWARE PLEASE? K THANKS
076萌SNS is a social network, courtesy of 076. It runs on GNU social, version 2.0.2-beta0, available under the GNU Affero General Public License.
All 076萌SNS content and data are available under the Creative Commons Attribution 3.0 license.