The issue is still open. https://github.com/ventoy/Ventoy/issues/2795
The last comment has this:
From Wikipedia, the free encyclopedia
Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).
Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.
Community icon by Alpár-Etele Méder, licensed under CC BY 3.0
The issue is still open. https://github.com/ventoy/Ventoy/issues/2795
The last comment has this:
That screenshot is from another site. An account named longpanda has also appeared on lemmy and had their post/replies removed because of impersonation suspicions.
I think it is wise to take extra care on this issue on what you read and trust.
Afaik that particular post is on the official Ventoy forum. Probably legit
The Lemmy one was fake
That is the owners account from the official forum, which is known to be real. The Lemmy account was a fake that copied their name from that account.
I'm in a similar boat to you; whether the blobs constitute a security threat seems to still be up in the air. I read through the issue thread on github a few months back and it seemed the vast majority of the blobs were built by scripts contained in the repository, but some weren't documented well, leading to uncertainty.
The comment by Long0x0 on Aug 05 lists a lot of the blob files.
Looks like contributor is busy with work. Always the risk with open source. If things aren't raised in a reasonable manner, I can imagine the temptation is to follow it up with a middle finger.
Many seemed to care about it enough to bash it, but not enough to create and maintain a fork. They just want to boss it over the maintainer.
Agreed: now that I'm looking at the whole thing, this looks like a story where the FOSS community left much to be desired.
Not fixed yet. People either quit, let their threat model allow Ventoy's shellscripts to git-commit bins, or built it from source (i.e. PKGBUILD or ebuild).
I thought one of them did comment about it and it was something like the uefi drivers taken from Fedora or something.
Blobs aren’t really a concern as they reference the sources which produce the same binaries, but there are suspicions of compromise due to the Lemmy comments mentioned in the thread. The official accounts’ comments alleviate some of that, though.