[0]: https://news.ycombinator.com/item?id=42351722
[1]: https://tukaani.org/xz-backdoor/
While skipping the released tarballs wouldn't have prevented the problem entirely, it would have made it much harder to hide.
[0]: https://news.ycombinator.com/item?id=42351722
[1]: https://tukaani.org/xz-backdoor/