Fwd: New on CTAN: cyrillic-modern
Jonathan Fine
jfine2358 at gmail.com
Mon May 6 13:14:52 CEST 2024
Arthur Rosendahl wrote:
> so it seems like someone decided it was time to add the package to CTAN
> -- probably the author himself.
>
Do we know that this is a genuine update, rather than a supply chain
attack? Recall the recent xz utils attack CVE-2024-3094. Malicious fonts
can change the meaning of a document.
Jonathan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://tug.org/pipermail/tex-live/attachments/20240506/41a53619/attachment.htm>
More information about the tex-live
mailing list.