On Sun, 2024-04-07 at 08:51 -0400, Michael Orlitzky wrote: > On Sun, 2024-04-07 at 14:35 +0200, Andreas K. Huettel wrote: > > > > Uhh, I dont really remember, I think some Chinese-sounding guy asked > > me for it... (j/k) > > It is remarkably bad timing. How it looks: Gentoo's response to the xz > incident is to have me rebuild my entire system with everything that > could possibly be linked to liblzma, linked to liblzma. Even on the > hardened profiles, and with no easy way to prevent it. So, what you're basically saying, is that the best Gentoo response right now would be to frantically remove LZMA support everywhere? I'm sure that would be so much better than our response of masking vulnerable versions and issuing a statement. -- Best regards, Michał Górny