Fwd: New on CTAN: cyrillic-modern

Jonathan Fine jfine2358 at gmail.com
Mon May 6 13:14:52 CEST 2024


Arthur Rosendahl wrote:

> so it seems like someone decided it was time to add the package to CTAN
> -- probably the author himself.
>

Do we know that this is a genuine update, rather than a supply chain
attack? Recall the recent xz utils attack CVE-2024-3094. Malicious fonts
can change the meaning of a document.

Jonathan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://tug.org/pipermail/tex-live/attachments/20240506/41a53619/attachment.htm>


More information about the tex-live mailing list.