96
submitted 23 hours ago by KarnaSubarna@lemmy.ml to c/linux@lemmy.ml
you are viewing a single comment's thread
view the rest of the comments
[-] umbrella@lemmy.ml 9 points 20 hours ago

isnt that well known though? AUR packages are built by third parties (eg users) and there were always warnings against just this, no?

[-] LeFantome@programming.dev 8 points 19 hours ago* (last edited 19 hours ago)

It is a well known risk but not something that was a real risk numerically. I mean, it still isn’t given the number of packages in the AUR.

This is a couple of malicious packages discovered in a short period though. Not a good sign. It was really impact the AUR if polluting it with malware became common.

You should always inspect AUR packages before installing them but few people do. Many would not even know what they were looking at.

[-] umbrella@lemmy.ml 11 points 19 hours ago* (last edited 19 hours ago)

yeah, that's almost as bad as those apps requiring you to pipe a remote script through sudo shell

[-] atzanteol@sh.itjust.works 5 points 19 hours ago

God I hate those. The worst way to distribute apps.

[-] umbrella@lemmy.ml 0 points 19 hours ago

especially when flatpaks exist now!

this post was submitted on 01 Aug 2025
96 points (97.1% liked)

Linux

56904 readers
745 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 6 years ago
MODERATORS