XZ backdoor story – Initial analysis

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • xz

    Discontinued XZ Utils [GET https://api.github.com/repos/tukaani-project/xz: 403 - Repository access blocked]

  • Very funny. This one:

    https://github.com/tukaani-project/xz/commits?author=thesame...

  • flathub

    Issue tracker and new submissions

  • > Nobody ever even audits the binary contents of flatpaks on flathub (were they actually built from the source? the author attests so!).

    IME/IIRC There aren't (or shouldn't be) any binary contents on Flathub that are submitted by the author, at least for projects with source available? You're supposed to submit a short, plain-text recipe instead, which then gets automatically built from source outside the control of the author.

    > The Flathub service then uses the manifest from your repository to continuously build and distribute your application on every commit.

    https://docs.flathub.org/docs/for-app-authors/submission/#ho...

    Usually the recipes should just list the appropriate URLs to get the source code, or, for proprietary applications, the official .DEBs. Kinda like AUR, but JSON/YAML. Easy to audit if you want:

    https://github.com/orgs/flathub/repositories

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts