

How do I know I’m not affected? I have to be fairly certain the packages identified are the only ones that were affected. That assesment could be wrong. If I 100% trust it, then yeah, I can trace if any of those packages/versions touched my machine. I would trust the package manager.




















This dipshit (me) hasn’t reinstalled their OS since 2014. Not Arch btw.
But if my OS was affected by a supply attack like this, I wouldn’t trust the analysis on which packages were affected and which weren’t so I’d likely nuke and pave as all my and my family data is here.