Over 100,000 Infected Repos Found on GitHub
Over 100,000 Infected Repos Found on GitHub
The Apiiro research team has detected a repo confusion campaign that has evolved and expanded, impacting over 100k GitHub repos with malicious code.
You're viewing a single thread.
Friends dont let friends install software that isn't signed.
Use apt.
20 3 ReplyLol apt
Or to frame it differently, use a package manager and not appimages etc.
12 0 ReplyAppImages actually do have (optional) support for signatures.
4 1 ReplyThey have no update feature afaik, how does this work? What verified this signature, the user?
2 0 ReplyIts a subcommand of the AppImage. The developer adds the signature to the AppImage and the user verifies it after download with the subcommand.
2 0 ReplyThats nice, didnt even know there was an interface for managing appimages?
1 0 Reply
I mean, yeah but not everything is available over apt. I try to use it whenever I can though
3 0 Reply