Karna@lemmy.ml to Linux@lemmy.ml · 4 天前Arch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comexternal-linkmessage-square66fedilinkarrow-up1184arrow-down12
arrow-up1182arrow-down1external-linkArch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comKarna@lemmy.ml to Linux@lemmy.ml · 4 天前message-square66fedilink
minus-squareAsonyxi@sh.itjust.workslinkfedilinkarrow-up3arrow-down2·3 天前Man I feel like I dodged a bullet switching to Fedora right before this AUR fuckery started to happen…
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up11·2 天前You don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
minus-squarechortle_tortle@mander.xyzlinkfedilinkarrow-up1·1 天前Sure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.
minus-squareScrollone@feddit.itlinkfedilinkarrow-up1·2 天前I wonder if Ubuntu PPAs are also compromised
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up3·2 天前The chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.
Man I feel like I dodged a bullet switching to Fedora right before this AUR fuckery started to happen…
You don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
Sure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.
I wonder if Ubuntu PPAs are also compromised
The chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.