• thingsiplay@lemmy.ml
    link
    fedilink
    arrow-up
    8
    ·
    edit-2
    45 minutes ago

    As an user of the AUR, this is devastating news to me. I am also guilty of accepting updates without reading the latest changes, even if yay asks me if I want to. This is a reminder to everyone to only install from the AUR for absolutely necessary stuff only, and only if you trust the maintainer. And to at least have a look if something suspicious is going in with the recent changes in the package recipe. AND to read in the communities and news.

    I don’t understand why there still no official announcement as a warning from the Archlinux team at https://archlinux.org/news/ . Is there a different place for security news specifically about the AUR to subscribe to?

    • trevor (he/they)@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      2
      ·
      35 minutes ago

      The fact that the Arch maintainers seem to prefer Reddit over their own fucking news channel is what made me switch from Arch years ago. I got sick of upstream breaking changes fucking my system because they wouldn’t notify people through official channels, only to find it later of /r/archlinux 🙄🙄🙄

      • Aatube@kbin.melroy.org
        link
        fedilink
        arrow-up
        1
        ·
        2 minutes ago

        since the 2022 grub incident, Arch has done a great job at notifying the news channel when “manual intervention required” AFAIK, and I don’t remember any instances of Arch maintainers only notifying Reddit (and I don’t think they notified Reddit for the grub incident either lol).

  • Aatube@kbin.melroy.org
    link
    fedilink
    arrow-up
    1
    ·
    15 minutes ago

    (hopefully this doesn’t read as blaming the victims instead of the attackers but) I personally don’t think it’s that complicated to read the updates to AUR packages. It’s not any more hard than only commenting after reading the links that people post here instead of just the headlines—which we all do, right?