Dear maintainers,

I have made an unsettling discovery:
http://www.nongnu.org/lzip/lzip_benchmark.html#busybox
"error detection in the xz format is silently broken."

If this is true (and it might be, because it provides a reproducer), why
is such a central project as GNU Coreutils being distributed in xz
format only? Shouldn't Coreutils switch to a safe-by-default compressed
format, as the above link suggests?

Thanks,

Ariel Santana.

Reply via email to