On Sat, Mar 30, 2024 at 11:47 AM Miroslav Suchý <msuchy(a)redhat.com> wrote:
Dne 30. 03. 24 v 1:25 odp. Chris Adams napsal(a):
Using a signed tarball is ideally better than a git tag (it's an extra
level of author attestation).
In this case signed tarball would not help at all. And git-tag would prevent this
attack.
Only because that person didn't think to check it in and tag it. They
very well could have since they had direct commit access.
--
真実はいつも一つ!/ Always, there's only one truth!