• 23 Posts
  • 381 Comments
Joined 10 months ago
Aquileo | cake
Cake day: September 23rd, 2025

Aquileo | help-circle




















  • sonofearth@lemmy.worldtoLinux@lemmy.mlArch Linux's AUR Sees More Than 400 Packages Compromised With Malware
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    1
    Aquileo | arrow-down
    1
    ·
    Aquileo | edit-2
    2 months ago

    I am not talking about the code. I am talking there are basically zero security measures.

    Edit:

    Demanding to do more work from volunteers which already do a lot of work for free is rude. If you want something done - do it yourself

    Then don’t make the platforms in the first place. This is such a stupid argument. It’s like someone creating a nuke but then ignoring the security measures and telling the rest of the people to take care of it. Genius. Should stop asking people to switch over to Linux as well then. Might as well I should just start bad mouthing and defaming Linux because users are left on their own by a hostile community.


  • That’s why we have warnings plastered all over.

    Plastering warning labels everywhere is a cheap way to shift 100% of the accountability onto the user. Security should be built into the AUR’s design (throttling new accounts, forcing forks for orphaned takeovers or maintainer-developer verification), not outsource your job to the users as a reading assignment before every system update. Humans are the final layer of defense not the first.

    Or maybe don’t use AUR blindly? You’re doing the equivalent of sudo curl — | bash… So only do it if you truly trust it.

    There is a massive difference between blindly curling a random script from the open web and using a centralized, organized community repository. Yes AUR helpers are not recommended but they exist and are used by majority of Arch users and you can’t expect the user to know code and pkgbuilds especially when distros like CachyOS make it so damn easy to install the OS with AUR being just a checkbox away.