@thesamesam @Conan_Kudo @lanodan @dalias @mirabilos Hmmm, so your concern is that a DevOps's workstation might get infected by malware from a compromised upstream repository? It is a valid security concern, but I think the xz scenario is a different problem, as a good build farm will isolate the build environment, i.e. after the build is done, the checkout/workspace is completely wiped.