When building from source, use the official strawberry-*.tar.xz, not the auto-generated .tar.gz or .zip
-
The latest release has this note at the top
When building from source, use the official strawberry-1.2.29.tar.xz, not the auto-generated .tar.gz or .zip
What is different about the .tar.xz file?
Why is it preferred over the autogenerated .tar.gz/.zip (which is just a collection of the files in the repo)? -
Looks like it's the apicredentials.h. Is this really the best way to distribute these? They must not be very secret since they're still in the .tar.xz.
I also think about this incident that could just as easily happen here, this has set us up for the same exact scenario: https://en.wikipedia.org/wiki/XZ_Utils_backdoor#:~:text=This modified file was not present in the git repository%3B it was only available from tar files