Bug#1065034: The courier packages on debian are ripe for a hostile takeover: An xz project compromise digression

2024-04-04 Thread ZHAO, Fei
Hi! Glad at least someone starts to talk about it. Thank you J MO for this. Normally the SYSOPs will just purge the official package and start to package themselves silently, however, Debian shouldn't work this way, it will be usable for novices and the attack of surface will become larger

Bug#1065034: The courier packages on debian are ripe for a hostile takeover: An xz project compromise digression

2024-04-01 Thread J Mo
Hello! https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1065034 This bug was filed with Debian a little over a month ago. Unfortunately, the courier packages on Debian have long been poorly maintained. Nobody seems to be willing to step up and help out. I know Markus Wanner is/was doing