

1·
11 days agoThanks for posting.
It has been my pleasure!
I was worried that it might have been forgotten about
The XZ utils supply chain attack has actually made the community more wary of blobs. Some projects were even prompted to come clean on this matter.
Fedora has also recently made a push towards reproducible builds. In the lwn.net article that discussed that push, one of Fedora’s spokespeople explicitly said that it would help combat supply chain attacks.
So, all in all, I can confidently say that it did leave a mark on the Linux landscape. Hopefully, this specific attack vector will not be as viable in the foreseeable future.
This is (at least somewhat of) a legit concern. But is mostly directed towards Flatpak’s limitations in its current implementation.
Have you ever wondered why openSUSE started working on (what would eventually become) Aeon while they had previously pioneered the BTRFS + Snapper workflow with Tumbleweed? I believe you may find the point of immutable distros in there 😉.