Quail4789@lemmy.mltoOpen Source@lemmy.ml•Ventoy source code contains some unknown BLOBs, still no word on the issue from the dev after monthsEnglish
9·
3 days agoYep, some people these are saying just 7 of the 150 binaries don’t have source or build info. Yeah, one binary is enough to do all the evil in the world, not that other binaries support reproducible builds anyway.
The amount of malware you can cram in a source-code patch without drawing attention vs. in a binary is vastly different.
There’s also the fact that if you want to ship binaries, you can just wget them from source during the build process. Not a perfect solution but much better than what’s ventoy doing. The source code updates works the same in every project because it has to. That’s why this is drawing more attention.