Open Source, Supply Chains, and Bears (oh my!)
I didn’t want to add my voice to the cacophony of hot takes about the xz backdoor incident because I’m sure many people are already sick of hearing about it.
However, there is something related to it that I’ve been noodling over for a while. As a compromise, I won’t summarize or rehash the xz incident to spare anyone from having to read that for the thousandth time.
Most of the postmortem conversation I’ve witnessed has centered around the burnout of open source developers, corporations’ relianc...
Read more at scottarc.blog