Session

What xz should have taught us (and didn’t)

The xz backdoor never appeared in the git repository. The release build assembled it from a tarball nobody outside that machine could regenerate. Most projects still release artifacts that could be compromised in the same way.

We’ll reconstruct how the attack was staged, from binary test fixtures to a build script that only misbehaved under the right conditions, then map each step onto its JVM equivalent: a plugin nobody reads, a test resource nobody opens, a fixture checked into a repo. Every defense gets the same blunt question. Would this have caught it?

Dependency scanning would not have. Reproducible builds and source-to-artifact verification would have had a real shot. You’ll leave ready to focus on controls that actually defend your builds, not just check boxes.

Brian Demers

Java Champion & Gradle Developer Advocate

Concord, New Hampshire, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top