# Moving away from "manual JLL packages" in the General registry

**URL:** <https://discourse.julialang.org/t/moving-away-from-manual-jll-packages-in-the-general-registry/135754>\
**Category:** Internals & Design\
**Created:** [February 20, 2026, 5:18pm UTC](https://discourse.julialang.org/t/moving-away-from-manual-jll-packages-in-the-general-registry/135754 "2026-02-20T17:18:02Z")\
**Posts on this page:** 1\
**Showing post:** 30

<div class="post-metadata">

**Author:** ![mbauman](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/mbauman/32/31082_2.png) [@mbauman](https://discourse.julialang.org/u/mbauman)\
**Post date:** [February 25, 2026, 6:37pm UTC](https://discourse.julialang.org/t/moving-away-from-manual-jll-packages-in-the-general-registry/135754/30 "2026-02-25T18:37:31Z")

</div>

Yep, that was the infamous XZ Utils issue, [NVD - CVE-2024-3094](https://nvd.nist.gov/vuln/detail/CVE-2024-3094). It used _both_ an opaque binary blob in a test file _and_ only activated it through _some_ build systems (_and_ required a malicious actor years to build trust and maintainership).

Yggdrasil actually built an XZ with the exploit code, but it wasn’t activated on _that_ build system. [PSA: backdoor in xz-utils and relevance for the Julia ecosystem](https://discourse.julialang.org/t/psa-backdoor-in-xz-utils-and-relevance-for-the-julia-ecosystem/112328)

---

_[View the full topic](https://discourse.julialang.org/t/moving-away-from-manual-jll-packages-in-the-general-registry/135754)._
