• starblursd@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 days ago

    Yea I use like 2 or 3 things from aur and they’re maintained by the developer… the recent aur attacks haven’t worried me a bit

    • nibbler@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 days ago

      ‘Bring maintained by their dev’ sounds kind of redundant. As long as you are not close with them that sounds like a bad take

      • starblursd@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        As in the official GitHub or whatever repo they’re using lists their aur package as an install message. So I’m not just downloading a potential clone/fake package with a similar name that could’ve been orphaned and taken over in the recent aur malware campaigns

      • xilophor@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        tbh I do feel like it’s somewhat relevant in this case since the packages that were compromised on the AUR were due to the AUR’s package transfer ability for unmaintained packages

        • nibbler@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 days ago

          But you still will not be notified when this changes?

          Admittedly the dev maintaining the aur sounds better than random person…