home.social

#archuserrepository — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #archuserrepository, aggregated by home.social.

fetched live
  1. Learn how to use the Arch User Repository (AUR) safely. Discover the lessons from the June 2026 AUR malware attack and protect your Arch Linux system.

    Full details here: ostechnix.com/use-the-aur-safe

    #ArchUserRepository #AUR #ArchLinux #Security #Malware #SupplyChainAttack #AtomicArch #Linux

  2. Learn how to use the Arch User Repository (AUR) safely. Discover the lessons from the June 2026 AUR malware attack and protect your Arch Linux system.

    Full details here: ostechnix.com/use-the-aur-safe

    #ArchUserRepository #AUR #ArchLinux #Security #Malware #SupplyChainAttack #AtomicArch #Linux

  3. OMG, every article about malware in #ArchUserRepository ends with something like "why don't they shut down the repository until all packages are checked?".
    That's misunderstanding of what AUR is. Arch offical packages are more curated and actually not affected. Only the user repo is. AUR is like a package forum, where everyone can create and share a package. No authority is curating it closely.
    It's like saying "why don't they shut down the arch forum until every mentioned bash command is checked" after somebody breaks their installation by blindly running an evil command like the favourite rm -rf / (don't run this).

    And I am not saying, that the attack is fine, and AUR is good tool. I think there should be some kind of maintainer reputation system added and package reputation system improved.

  4. OMG, every article about malware in #ArchUserRepository ends with something like "why don't they shut down the repository until all packages are checked?".
    That's misunderstanding of what AUR is. Arch offical packages are more curated and actually not affected. Only the user repo is. AUR is like a package forum, where everyone can create and share a package. No authority is curating it closely.
    It's like saying "why don't they shut down the arch forum until every mentioned bash command is checked" after somebody breaks their installation by blindly running an evil command like the favourite rm -rf / (don't run this).

    And I am not saying, that the attack is fine, and AUR is good tool. I think there should be some kind of maintainer reputation system added and package reputation system improved.