I am not sure under what usecases, you will end up with a lot of stale branches. And git fetch -pa should fix it locally
15 karma · joined June 23, 2022
I am not sure under what usecases, you will end up with a lot of stale branches. And git fetch -pa should fix it locally
For example oss-fuzz was building xz by cloning the github repo directly. There was never a chance for oss-fuzz to discover the backdoor, because only the tarball had it, not the repo itself. So that oss-fuzz PR might genuinely just be a genuine thing unrelated to the backdoor.
a) absolutely nobody uses cmake to build this packet
b) if you try to build the packet with cmake and -DENABLE_SANDBOX=landlock, the build just fails: https://i.imgur.com/7xbeWFx.png
The "." does not disable sandboxing, it just makes it impossible to build with cmake. If anyone had ever actually tried building it with cmake, they would get the error and realize that something is wrong. It makes absolutely no sense that this would be malicious attempt to reduce security.