Karna@lemmy.ml to Linux@lemmy.ml · 14 days agoArch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comexternal-linkmessage-square72linkfedilinkarrow-up1200arrow-down14
arrow-up1196arrow-down1external-linkArch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comKarna@lemmy.ml to Linux@lemmy.ml · 14 days agomessage-square72linkfedilink
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up12·12 days agoYou don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
minus-squareScrollone@feddit.itlinkfedilinkarrow-up1·12 days agoI wonder if Ubuntu PPAs are also compromised
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up3·12 days agoThe chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.
minus-squarechortle_tortle@mander.xyzlinkfedilinkarrow-up1·11 days agoSure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.
You don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
I wonder if Ubuntu PPAs are also compromised
The chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.
Sure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.