

6·
10 days agoNo, they’re talking about their own dependencies


No, they’re talking about their own dependencies


Not disagreeing with you, but since the author is asking about GitHub… the XZ GitHub didn’t actually have any malicious code. Only the website tarbal did.
https://harshanu.space/en/tech/ccc-vs-gcc/ has a good overview how bad it really is