Announcement

Collapse
No announcement yet.

Gentoo's GitHub site hacked

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Gentoo's GitHub site hacked

    https://nakedsecurity.sophos.com/201...d-compromised/

    The Gentoo team didn’t beat around the bush, and quickly published an unequivocal statement about the breach.
    The Gentoo GitHub repository is only a secondary copy of the main Gentoo source code.
    The main Gentoo repository is intact.
    All changes in the main Gentoo repository are digitally signed and can therefore be verified.
    As far as we know, the main Gentoo signing key is safe, so the digital signatures are reliable.
    and
    This does NOT affect any code hosted on the Gentoo infrastructure. Since the master Gentoo ebuild repository is hosted on our own infrastructure and since Github is only a mirror for it, you are fine as long as you are using rsync or webrsync from gentoo.org.

    Also, the gentoo-mirror repositories including metadata are hosted under a separate Github organization and likely not affected as well.

    All Gentoo commits are signed, and you should verify the integrity of the signatures when using git.

    More updates will follow.
    Kubuntu 20.04

    #2
    Has M$ taken control of github yet?
    "A nation that is afraid to let its people judge the truth and falsehood in an open market is a nation that is afraid of its people.”
    – John F. Kennedy, February 26, 1962.

    Comment


      #3
      Originally posted by GreyGeek View Post
      Has M$ taken control of github yet?
      Not yet, the deal will finalized "by the end of the year".

      Yeah, the headlines are perhaps slightly misleading, as Gentoo, like KDE and other projects, only use github as a mirror. The real building and work is done on their own servers and git instances.

      Comment

      Working...
      X