Karna@lemmy.ml to Linux@lemmy.ml · 2 months agoArch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comexternal-linkmessage-square72linkfedilinkarrow-up1200arrow-down13
arrow-up1197arrow-down1external-linkArch Linux AUR Under Another Wave Of Malicious Packages, Package Adoptions Haltedwww.phoronix.comKarna@lemmy.ml to Linux@lemmy.ml · 2 months agomessage-square72linkfedilink
minus-squareAsonyxi@sh.itjust.workslinkfedilinkarrow-up5arrow-down2·2 months agoMan I feel like I dodged a bullet switching to Fedora right before this AUR fuckery started to happen…
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up12·2 months agoYou don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
minus-squareScrollone@feddit.itlinkfedilinkarrow-up1·2 months agoI wonder if Ubuntu PPAs are also compromised
minus-squaremotruck@lemmy.ziplinkfedilinkarrow-up3·2 months agoThe chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.
minus-squarechortle_tortle@mander.xyzlinkfedilinkarrow-up1·2 months agoSure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.
minus-squaredarkstar@sh.itjust.workslinkfedilinkEnglisharrow-up1·1 month agoSame. I was on Cachy for a few months but recently switched back to Fedora. I’m sleeping very peacefully.
Man I feel like I dodged a bullet switching to Fedora right before this AUR fuckery started to happen…
You don’t have to use AUR to use Arch. Just like PPA for Ubuntu or Fedora’s Copr.
I wonder if Ubuntu PPAs are also compromised
The chances malicious packages live in PPA now is quite high. Perhaps their adoption procedures are not conducive to the same type of attack AUR is experiencing.
Sure, but as a user it seems like a non-trivial number of packages are only on the AUR vs other distros.
Same. I was on Cachy for a few months but recently switched back to Fedora. I’m sleeping very peacefully.