Karna@lemmy.ml to Linux@lemmy.ml · 14 days agoArch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comexternal-linkmessage-square72linkfedilinkarrow-up1171arrow-down13cross-posted to: archlinux@lemmy.ml
arrow-up1168arrow-down1external-linkArch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comKarna@lemmy.ml to Linux@lemmy.ml · 14 days agomessage-square72linkfedilinkcross-posted to: archlinux@lemmy.ml
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up12·12 days agoYou don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
minus-squareScrollone@feddit.itlinkfedilinkarrow-up1·12 days agoI wonder if Ubuntu PPAs are also compromised
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up3·12 days agoThe chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.
minus-squarechortle_tortle@mander.xyzlinkfedilinkarrow-up1·10 days agoSure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.
You don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
I wonder if Ubuntu PPAs are also compromised
The chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.
Sure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.