I haven’t heard a peep about the security status of AUR since the headlines about malware injections into thousands of packages. I’ve ensured that none of my installed software is affected by the attack (to the best of my ability), but I’ve held off on my regular yay -Syu since then. What has you all done to keep your machine updated but clean?

And is there any update from AUR maintainers that the situation is under control? Most of my installed AUR packages simply don’t exist in the official Arch repos, so if not I’d have to look for other sources.

  • Handles@leminal.spaceOP
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 days ago

    Thanks for all the replies! In a nutshell,

    1. “Safe” is a relative concept with AUR.
    2. Most of the affected packages were unmaintained, and probably shouldn’t be installed anyway.
    3. Read the diff’s before updating 👍