<infinisil>
Which embeds git commit info dynamically into the archive created by github
<infinisil>
And specifically the %d there isn't deterministic, it changes depending on branches that currently point to the commit
<infinisil>
I reported this to the git security mailing list, showing how this could be used to change github tarballs by only creating branches in the repo, without creating a new commit
<infinisil>
Have never heard back of them though, which is why I'm mentioning it here now
hmpffff_ has joined #nixos-security
hmpffff has quit [Ping timeout: 272 seconds]
infinisil has quit [Quit: Configuring ZNC, sorry for the joins/quits!]
infinisil has joined #nixos-security
justanotheruser has quit [Ping timeout: 256 seconds]
hmpffff has joined #nixos-security
hmpffff_ has quit [Ping timeout: 272 seconds]
anselmolsm has joined #nixos-security
justanotheruser has joined #nixos-security
anselmolsm has quit [Quit: Konversation terminated!]