Strit

u/Strit@lemmy.linuxuserspace.show
12 posts · 859 comments

Recent posts

Recent comments

And you can check the shasum of the binary to see if it actually matches that provided by the developers of the application.

A malicious PKGBUILD, which is what is being talked about, you would see that it downloads a binary that does not come from the developers and so you should not install that.

If the attack happens on the developers repo, not even Linux repository packages would be safe at that point (eg, the xz heist).

on SSH Pilot 5.7.2 released · c/linux · 2 pts · 9d

Looks like a really neat tool though. If you often work in multiple SSH sessions it seems really handy. :)

on Auth apps · c/selfhosted · 3 pts · 13d

I use my Nextcloud instance as a OIDC provider for all my other apps.