TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: What can we do as a community to prevent XZ-like attacks in future?

7 点作者 kjok大约 1 年前

3 条评论

lulznews大约 1 年前
The companies making billions (trillions?) off this stuff could actually fund it and stop relying on exploiting naive code monkeys.
SeriousM大约 1 年前
- Enforcement of blob-generating code to be committed too and a test to check if someone has tampered with the blobs. Or generate test-blobs just before execution. In short: habe everything readable. - Once a project is referenced just over a reasonable threshold the maintainer should be checked and may transfer the ownership if the new maintainer is verified too.
talldayo大约 1 年前
Read pull requests