• Eldritch@piefed.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 hours ago

      Yeah, Python has been a massive vulnerability for a long while. And the AUR has similar issues. This is only getting widespread coverage now. But it’s always been a risk.

    • CaptDust@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 hours ago

      Well, those are mostly extension libraries, stuff “normally” installed using pip. Arch is kind of unique that they encourage using system aur over pip, npm and other package managers. While it is a big radius, none of the python packages stick out to me, but maybe I just haven’t encountered the popular ones.

      • esc@piefed.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        33 minutes ago

        It isn’t really all that unique? Debian does it, el does it, probably almost any popular distro?

      • iocase@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 hours ago

        The attackers specifically targeted orphaned projects on AUR so it’s no wonder most of those aren’t familiar to us.