ParentFull threadjoeyh·Running xz in a sandbox would not prevent an attack that causes it to modify source code in a .tar.xz that is being streamed through it.View on HN