• Successful_Try543@feddit.de
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    3 months ago

    Wasn’t the problem that it the backdoor was not present in the source code on GitHub, but was in the source tarball? So as long as one reads the code that one actually builds from should be fine.

    • SuperIce@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      3 months ago

      A line of code that enables the backdoor was out present in the tarball. The actual code was obfuscated within an archive used for the unit testing.