I haven’t heard a peep about the security status of AUR since the headlines about malware injections into thousands of packages. I’ve ensured that none of my installed software is affected by the attack (to the best of my ability), but I’ve held off on my regular yay -Syu since then. What has you all done to keep your machine updated but clean?

And is there any update from AUR maintainers that the situation is under control? Most of my installed AUR packages simply don’t exist in the official Arch repos, so if not I’d have to look for other sources.

  • Nibodhika@lemmy.world
    link
    fedilink
    arrow-up
    2
    arrow-down
    3
    ·
    9 hours ago

    This reads like someone asking whether it’s safe to leave your front door unlocked again because he read about a bunch of people using open front doors to rob them.

    It never was safe, it never will be safe, you’re trading convenience for safety, you’re supposed to review the PKGBUILDS to ensure they’re safe, if you can’t do that you shouldn’t risk it.

    This is why I hate when Arch (yes, even Cachy or whatever is the current “easy” Arch) is recommended for new users. Arch assumes you know what you’re doing, it expects you to read the manual, and it doesn’t have kid gloves. You will get hit in the face by this and many other similar things, and will be told “it was in the manual”.