Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on sh.itjust.works

1 reply

Who would have thought that package repo concepts with automatic fetch during build could be a security risk?

Static linking makes this worse.

Granted, static linking for web apps is great and far better then the alternatives.

But now we deliver static linked desktop and system packages. The security nightmares just began (looking at you canonical)

5

You reached the end

North Korean Hackers Tied to Rust Supply Chain Attack - Infosecurity Magazine | Spyke