18
submitted 2 days ago by halm@leminal.space to c/archlinux@lemmy.ml

I haven't heard a peep about the security status of AUR since the headlines about malware injections into thousands of packages. I've ensured that none of my installed software is affected by the attack (to the best of my ability), but I've held off on my regular yay -Syu since then. What has you all done to keep your machine updated but clean?

And is there any update from AUR maintainers that the situation is under control? Most of my installed AUR packages simply don't exist in the official Arch repos, so if not I'd have to look for other sources.

you are viewing a single comment's thread
view the rest of the comments
[-] dadarobot@lemmy.ml 4 points 2 days ago

another thing to note: after an update, when your aur tool says you have orphaned packages installed, highly consider removing them.

if you want to keep them for whatever reason, try to remember (or write them down) so if they get an update out of the blue, you can scruitinize the pkgbuild

[-] definitemaybe@lemmy.ca 2 points 1 day ago

It only takes a few moments to scan the diffs in a pkgbuild. It's not a big ask.

this post was submitted on 26 Jul 2026
18 points (100.0% liked)

Arch Linux

9875 readers
5 users here now

The beloved lightweight distro

founded 6 years ago
MODERATORS