← Back to context

Comment by theultdev

2 years ago

So the worry is the Zed team themselves will inject something into the binary?

The xz backdoor was an example of exploiting this disconnect. It was not present in the repository, it was inserted only into the release artifacts. Anyone getting xz by checking out the repository and building it themselves, would not be affected by it.