Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Replace Sodium blob with git submodule #188

Closed
REALERvolker1 opened this issue Jan 16, 2025 · 3 comments
Closed

Replace Sodium blob with git submodule #188

REALERvolker1 opened this issue Jan 16, 2025 · 3 comments

Comments

@REALERvolker1
Copy link

Good morning.

I was looking through the source code of this mod, when I noticed a .jar file that I could only view as raw. Pardon me if this is a silly issue, I am not very familiar with the Java language, but it seems like you are statically linking to this dependency. It would be better for build reproducibility if this was addressed. I propose adding it as a git submodule, so the entire source tree could be explored, but ydy.

As of right now, I cannot verify that this mod is not malicious. It would do me (any many others in the anarchy community) a great service if you could change how this is done. Pardon my paranoia -- I just remember the XZ and Fracturiser situations, and I don't want history to repeat itself, especially as members of my group have used this mod and it could have potentially exposed base coordinates, passwords, etc. We just don't know without being able to check it.

Thank you for your time, rfresh.

@rfresh2
Copy link
Owner

rfresh2 commented Jan 16, 2025

this mod is a compile only dependency. its not included in xaeroplus's output jar, nor can it change anything about xaeroplus' output jar.

Feel free to compare file hashes with their official alpha build: https://discord.com/channels/602796788608401408/1260082015479271535/1260082015479271535

@FaxHack
Copy link

FaxHack commented Jan 16, 2025

The .jar file is not malicious i can confirm that I have checked it and as @rfresh2 stated "this mod is a compile-only dependency. it's not included in Xaeroplus's output jar, nor can it change anything about Xaeroplus' output jar.

Feel free to compare file hashes with their official alpha build: https://discord.com/channels/602796788608401408/1260082015479271535/1260082015479271535"

@rfresh2
Copy link
Owner

rfresh2 commented Jan 19, 2025

I have removed the sodium 0.6 settings integration for 1.20.1 in XP 2.25.1 because I have now seen that sodium is no longer intending to release the 0.6 backport to 1.20.1.

@rfresh2 rfresh2 closed this as completed Jan 19, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants