In the wake of the malicious compromise of xz, we should take some reasonable steps here to try to mitigate issues in the future. Notably, the major avenue of compromise involved a malicious modification to the m4 scripts used in building xz through Autotools.
xz
I propose we consider doing three things:
These are just my early morning thoughts based on what I think would be appropriate for us to do. We could also put a recommendation that packagers consider engaging with upstreams to convince them to convert away from Autotools to something more supportable, but I'm not sure that's feasible advice.
Seems reasonable. If the FPC thinks this is a good idea, this should probably be a change proposal, right, similar to the one that sets build flags by default?
If we want to mass change existing packages, yes, a change proposal will be needed.
Log in to comment on this ticket.