<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[When building from source, use the official strawberry-*.tar.xz, not the auto-generated .tar.gz or .zip]]></title><description><![CDATA[<p dir="auto">The latest release has this note at the top</p>
<blockquote>
<p dir="auto">When building from source, use the official strawberry-1.2.29.tar.xz, not the auto-generated .tar.gz or .zip</p>
</blockquote>
<p dir="auto">What is different about the .tar.xz file?<br />
Why is it preferred over the autogenerated .tar.gz/.zip (which is just a collection of the files in the repo)?</p>
]]></description><link>https://forum.strawberrymusicplayer.org/topic/6076/when-building-from-source-use-the-official-strawberry-tar-xz-not-the-auto-generated-tar-gz-or-zip</link><generator>RSS for Node</generator><lastBuildDate>Thu, 10 Sep 2026 19:13:18 GMT</lastBuildDate><atom:link href="https://forum.strawberrymusicplayer.org/topic/6076.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 10 Sep 2026 12:31:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to When building from source, use the official strawberry-*.tar.xz, not the auto-generated .tar.gz or .zip on Thu, 10 Sep 2026 18:35:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="mention plugin-mentions-user plugin-mentions-a" href="https://forum.strawberrymusicplayer.org/uid/3805">@tebriel</a><br />
Do you have a better suggestion? The only other alternative as far as I can see is to have every user create their own, and that would cause hassle for a lot of users.</p>
<p dir="auto">It's not very secret, but it leaves them off the git repository, and they are obfuscated in the tar.xz, not directly in clear-text like before. This makes it more unlikely that other projects that fork of strawberry continue to use the same API credentials.</p>
<p dir="auto">The tar.xz creation is automated through GitHub CI and attached to the release, the whole process is in the open. It's possible to compare the sha256 from the github actions job run log to the actual sha256 in the release on GitHub. There are plenty of projects that manually create and upload the source-code tarball. And I hope that Linux distros have learned from the xz backdoor and have better security to scan the code for security issues. AI has also come a long way since then.</p>
]]></description><link>https://forum.strawberrymusicplayer.org/post/9371</link><guid isPermaLink="true">https://forum.strawberrymusicplayer.org/post/9371</guid><dc:creator><![CDATA[jonas]]></dc:creator><pubDate>Thu, 10 Sep 2026 18:35:27 GMT</pubDate></item><item><title><![CDATA[Reply to When building from source, use the official strawberry-*.tar.xz, not the auto-generated .tar.gz or .zip on Thu, 10 Sep 2026 16:53:11 GMT]]></title><description><![CDATA[<p dir="auto">Looks like it's the apicredentials.h. Is this really the best way to distribute these? They must not be very secret since they're still in the .tar.xz.</p>
<p dir="auto">I also think about this incident that could just as easily happen here, this has set us up for the same exact scenario: <a href="https://en.wikipedia.org/wiki/XZ_Utils_backdoor#:~:text=This%20modified%20file%20was%20not%20present%20in%20the%20git%20repository%3B%20it%20was%20only%20available%20from%20tar%20files" rel="nofollow ugc">https://en.wikipedia.org/wiki/XZ_Utils_backdoor#:~:text=This modified file was not present in the git repository%3B it was only available from tar files</a></p>
]]></description><link>https://forum.strawberrymusicplayer.org/post/9369</link><guid isPermaLink="true">https://forum.strawberrymusicplayer.org/post/9369</guid><dc:creator><![CDATA[tebriel]]></dc:creator><pubDate>Thu, 10 Sep 2026 16:53:11 GMT</pubDate></item></channel></rss>