• malloc@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    4 hours ago

    Is this the first time AUR has been compromised to this degree?

    Given how changes are often unvetted, I am surprised this hasn’t occurred before.

    • De Lancre@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      50 minutes ago

      Is this the first time AUR has been compromised to this degree?

      I do believe so, yes. There was couple of cases in last year, but never to this extend. If I understand correctly, reading arch thread, it something to do with the fact that anyone can “adopt” orphaned package on AUR. Which is kinda wild.

    • tempest@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      2 hours ago

      A lot of the AUR is just build scripts for GitHub repos …