• Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    When building from source, use the official strawberry-*.tar.xz, not the auto-generated .tar.gz or .zip

    Scheduled Pinned Locked Moved
    Development
    1
    2
    8
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tebriel
      last edited by

      The latest release has this note at the top

      When building from source, use the official strawberry-1.2.29.tar.xz, not the auto-generated .tar.gz or .zip

      What is different about the .tar.xz file?
      Why is it preferred over the autogenerated .tar.gz/.zip (which is just a collection of the files in the repo)?

      1 Reply Last reply Reply Quote 0
      • T
        tebriel
        last edited by

        Looks like it's the apicredentials.h. Is this really the best way to distribute these? They must not be very secret since they're still in the .tar.xz.

        I also think about this incident that could just as easily happen here, this has set us up for the same exact scenario: https://en.wikipedia.org/wiki/XZ_Utils_backdoor#:~:text=This modified file was not present in the git repository%3B it was only available from tar files

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Powered by NodeBB | Contributors