Karna@lemmy.ml to Linux@lemmy.ml · 8 months agoUbuntu 24.04 Beta Delayed Due To XZ Nightmarewww.phoronix.comexternal-linkmessage-square7fedilinkarrow-up1114arrow-down14cross-posted to: [email protected][email protected][email protected][email protected]
arrow-up1110arrow-down1external-linkUbuntu 24.04 Beta Delayed Due To XZ Nightmarewww.phoronix.comKarna@lemmy.ml to Linux@lemmy.ml · 8 months agomessage-square7fedilinkcross-posted to: [email protected][email protected][email protected][email protected]
minus-squarerotopenguin@infosec.publinkfedilinkEnglisharrow-up40arrow-down2·edit-28 months agoMy $0.05 reading of it is that they want to hose down the build servers* and start clean, in case if the attacker escaped the sandboxing there. * (the computers that compile all of the new packages from source, not web servers that are handing out finished deb binaries to the public.)
minus-squarestyle99@kbin.sociallinkfedilinkarrow-up31·8 months agoThey’re rebuilding all the newer builds “out of an abundance of caution.” The servers themselves obviously don’t run on experimental software.
minus-squareAvid Amoeba@lemmy.calinkfedilinkarrow-up5·8 months agoThat would make sense if they ran servers on non-LTS release. Do they do that?
minus-squarerollingflower@lemmy.kde.sociallinkfedilinkarrow-up3·8 months agoThey dont run experimental software on their build servers.
My $0.05 reading of it is that they want to hose down the build servers* and start clean, in case if the attacker escaped the sandboxing there.
* (the computers that compile all of the new packages from source, not web servers that are handing out finished deb binaries to the public.)
They’re rebuilding all the newer builds “out of an abundance of caution.” The servers themselves obviously don’t run on experimental software.
This.
That would make sense if they ran servers on non-LTS release. Do they do that?
They dont run experimental software on their build servers.