Skip to content

Commit

Permalink
post: added chapter on recursive checks
Browse files Browse the repository at this point in the history
  • Loading branch information
himazawa committed Mar 31, 2024
1 parent 23dc74d commit 27eb142
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions content/posts/xz-backdoor/index.en.md
Original file line number Diff line number Diff line change
Expand Up @@ -150,6 +150,8 @@ Also take in considerations that we are humans, and we make errors. Passing a co
### Enterprise vs Individual
This is a controversial topic because there are projects that are maintained by individuals that are well structured but usually relying on (large) enterprise projects will ensure their SDLC best practices are followed, money are keeping the project alive, and a big company is less likely to go all in and backdoor their project on purpose. Again, this just increases the probablity, don't take it for granted ;)

### Recursive controls
The project you are including will probably also have dependencies, make sure the same scrutiny is applied by the project maintainers on their supply chain to avoid indirect compromission.

## Resources

Expand Down

0 comments on commit 27eb142

Please sign in to comment.