185
submitted 1 month ago* (last edited 1 month ago) by tomenzgg@midwest.social to c/linux@programming.dev
you are viewing a single comment's thread
view the rest of the comments
[-] rumba@lemmy.zip 2 points 1 month ago

It's all fun and games until some asshole slips something into your trusted package manager.

Exploits are the deal pain

[-] fruitycoder@sh.itjust.works 1 points 1 month ago

Yep SLSA is more than just a trusted end point. Package signatures, reproducible builds, SBOMs, signed commits and more!

this post was submitted on 27 Oct 2025
185 points (100.0% liked)

Linux

10461 readers
400 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 2 years ago
MODERATORS