this post was submitted on 27 Oct 2025
170 points (92.9% liked)
Linux
9942 readers
2055 users here now
A community for everything relating to the GNU/Linux operating system (except the memes!)
Also, check out:
Original icon base courtesy of lewing@isc.tamu.edu and The GIMP
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
It's all fun and games until some asshole slips something into your trusted package manager.
Exploits are the deal pain
Yep SLSA is more than just a trusted end point. Package signatures, reproducible builds, SBOMs, signed commits and more!