Karna@lemmy.ml to Linux@lemmy.ml · 2 months agoArch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comexternal-linkmessage-square72linkfedilinkarrow-up1201arrow-down13cross-posted to: archlinux@lemmy.ml
arrow-up1198arrow-down1external-linkArch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comKarna@lemmy.ml to Linux@lemmy.ml · 2 months agomessage-square72linkfedilinkcross-posted to: archlinux@lemmy.ml
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up12·2 months agoYou don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
minus-squareScrollone@feddit.itlinkfedilinkarrow-up1·2 months agoI wonder if Ubuntu PPAs are also compromised
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up3·2 months agoThe chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.
minus-squarechortle_tortle@mander.xyzlinkfedilinkarrow-up1·2 months agoSure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.
You don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
I wonder if Ubuntu PPAs are also compromised
The chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.
Sure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.