Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The xz debacle happened partiallybecause the generated autoconf code was provided.

The code was only provided in a roundabout way that was deliberately done to evade manual inspection, so that's not a failure of checking in generated code, that's a failure of actually building a binary from the artifacts that we expect it to be built from. Suffice to say, cutting out the Turing-complete crap from our build systems is only one of many things that we need to fix.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: