The Xz story from [last month](https://simonwillison.net/2024/Apr/5/everything-i-know-about-the-xz-backdoor/), where a malicious contributor almost managed to ship a backdoor to a number of major Linux distributions, included a nasty detail where presumed collaborators …
Which projects?
The latest one was LSPatch. Did so much for me. Last message from the maintainer was something along the lines of ‘Seems like people are not happy with the project so I’m dropping it’.
I don’t even know what that is and I want to thank them for the project…