• thingsiplay@lemmy.ml
    link
    fedilink
    arrow-up
    11
    ·
    edit-2
    1 hour ago

    As an user of the AUR, this is devastating news to me. I am also guilty of accepting updates without reading the latest changes, even if yay asks me if I want to. This is a reminder to everyone to only install from the AUR for absolutely necessary stuff only, and only if you trust the maintainer. And to at least have a look if something suspicious is going in with the recent changes in the package recipe. AND to read in the communities and news.

    I don’t understand why there still no official announcement as a warning from the Archlinux team at https://archlinux.org/news/ . Is there a different place for security news specifically about the AUR to subscribe to?

  • starblursd@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    8 minutes ago

    There were announcements and security ping in the arch Linux discord… But I wish they’d be more vocal on this outside discord especially given discords controversy as of late

  • Aatube@kbin.melroy.org
    link
    fedilink
    arrow-up
    1
    ·
    30 minutes ago

    (hopefully this doesn’t read as blaming the victims instead of the attackers but) I personally don’t think it’s that complicated to read the updates to AUR packages. It’s not any more hard than only commenting after reading the links that people post here instead of just the headlines—which we all do, right?