https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65
Pretty bad, if they had implemented TUF, maybe not so bad?
https://nesbitt.io/2026/05/24/signing-is-for-the-bad-days.html
Discussion
https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65
Pretty bad, if they had implemented TUF, maybe not so bad?
https://nesbitt.io/2026/05/24/signing-is-for-the-bad-days.html
@andrewnez I think signing would have solved this, particularly with short lived certificates on a transparency log.
What I haven't seen is a real world use case where TUF would have prevented an attack. The demos show scenarios like a trusted signer that ingests a bad input that downstream users somehow know is bad. But in the real world, users don't know good from bad hashes.
@bmitch agreed, I've long been thinking about setting up @ecosystems as a witness that clients could double check with.