Apparently not, you can check commits in https://git.tukaani.org/?p=xz.git;a=summary the first authored commit was 2022-01-28, then long time nothing until 2022-06-10, the first merge as committer was 2022-12-16.
openpgp4fpr:2265D7F3A7B095CC3918630B6A6CD5B765632D3A
Apparently not, you can check commits in https://git.tukaani.org/?p=xz.git;a=summary the first authored commit was 2022-01-28, then long time nothing until 2022-06-10, the first merge as committer was 2022-12-16.
Making one a maintainer (with merge and possibly even direct commit/push permissions) is handing them a key to the kingdom. Recruiting a maintainer out of the blue without them being already contributor and long term participant in the project is questionable.
Of the xz/liblzma backdoor incident.
Malicious account holders with a long term goal need to build reputation. It doesn’t matter much that such an app isn’t a dependency of other software.
This is how one attracts and invites Jia Tan and Hans Jansen types.
First choice GIMP. Then, Digikam has an image editor that provides a number of tools. Not as detailed and sophisticated as GIMP but does most things needed.
RCE CVEs are a thing.
It’s probably sufficient to be able to take over the browser remotely.
Lol, “the only way a team can effectively use TOTP”, really? Many paid PWMs doing it already isn’t a good excuse.
It’s enough if they have access to the browser.
I don’t have much to add to the edited version of that comment in that topic there: https://lemmy.ml/comment/8930011
Hell no, having OTP in the browser kinda defeats all 2FA and makes it 1FA again.
If you like command line: TaskWarrior has due and recurring tasks and weighted priorities and more. There are also some frontends under Tools, search for GUI, but to me they are more cumbersome than CLI. If you’re into Vim then vit might come handy.
See also Recurring tasks with taskwarrior.
If you installed the original legit package it can’t be updated with such fake one (without uninstalling and installing the bad one) as the signatures won’t match. If you initially install the bad package then yes of course.
Yes, Info-ZIP can do that, it’s called a split archive. man zip
and -s
splitsize or --split-size
splitsize
The Power Off button gives a great quality of life experience.
And with that they are out.
OP seems to be on a crusade, cross-posting this to 4 lemmy communities.
Anyway, this: https://github.com/organicmaps/organicmaps/issues/6773#issuecomment-1838123926
As Jean said, it will have a setting to toggle the Kayak integration and it will be opt-in (disabled by default) to avoid an Anti-Feature on F-Droid.
That already is sufficient to stay away.
Additionally, node operators are rewarded in $OXEN for services offered on nodes, mined on the Oxen blockchain.
If these nodes cease to operate, Session will be dead.
Whatever client you use, there is no privacy with Discord. Period. Full stop.