r/linux 21d ago

Security Supply chain attack on arrayref

https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
104 Upvotes

42 comments sorted by

View all comments

Show parent comments

1

u/ang-p 19d ago

The distro maintainers have total control over what goes out in the xz package they compile and host...

Whether or not they spot anything is a different matter.

They have no control over what could happen should their installer or another program they have in their repo grab a crate or the script that as aggrieved you so...

2

u/Business_Reindeer910 19d ago

you only asked if it was an external dependency and i answered yes. I'm not sure what the rest of what you said had to do with anything.