this post was submitted on 27 Oct 2025
        
      
      171 points (93.0% liked)
      Linux
    9996 readers
  
      
      358 users here now
      A community for everything relating to the GNU/Linux operating system (except the memes!)
Also, check out:
Original icon base courtesy of lewing@isc.tamu.edu and The GIMP
        founded 2 years ago
      
      MODERATORS
      
    you are viewing a single comment's thread
view the rest of the comments
    view the rest of the comments
It's all fun and games until some asshole slips something into your trusted package manager.
Exploits are the deal pain
Yep SLSA is more than just a trusted end point. Package signatures, reproducible builds, SBOMs, signed commits and more!