Closed maltfield closed 2 years ago
This issue has been automatically marked as inactive because it has not had recent activity.
@maltfield thanks for opening the issue - would you be willing to make a PR for this?
This issue has been automatically marked as inactive because it has not had recent activity.
@lumjjb I would like to help to do this PR
This issue has been automatically marked as inactive because it has not had recent activity.
@lumjjb can the PR be reviewed so this can be closed?
sorry that i missed this - i added a comment and updated the branch.
Once we address the comments and CI passes ill merge it!
This curated list of Supply Chain Compromises is awesome, thanks for maintaining it!
I noticed that the Monero wallet's compromised release from 2019-11-18 is not listed in this repo.
Considering that Monero is widely considered to be the most popular/secure privacy cryptocurrency, it's easily one of the most security-critical packages that you wouldn't want to become victim to supply chain attacks..
Fortunately, they did have release signing in-place, so users were quickly able to identify the issue and address it. But it's yet another cautionary tale for project maintainers that blindly trust their infrastructure.
Further reading on this incident: