18
submitted 2 days ago by halm@leminal.space to c/archlinux@lemmy.ml

I haven't heard a peep about the security status of AUR since the headlines about malware injections into thousands of packages. I've ensured that none of my installed software is affected by the attack (to the best of my ability), but I've held off on my regular yay -Syu since then. What has you all done to keep your machine updated but clean?

And is there any update from AUR maintainers that the situation is under control? Most of my installed AUR packages simply don't exist in the official Arch repos, so if not I'd have to look for other sources.

you are viewing a single comment's thread
view the rest of the comments
[-] Nibodhika@lemmy.world 4 points 1 day ago

This reads like someone asking whether it's safe to leave your front door unlocked again because he read about a bunch of people using open front doors to rob them.

It never was safe, it never will be safe, you're trading convenience for safety, you're supposed to review the PKGBUILDS to ensure they're safe, if you can't do that you shouldn't risk it.

This is why I hate when Arch (yes, even Cachy or whatever is the current "easy" Arch) is recommended for new users. Arch assumes you know what you're doing, it expects you to read the manual, and it doesn't have kid gloves. You will get hit in the face by this and many other similar things, and will be told "it was in the manual".

[-] halm@leminal.space 1 points 1 day ago

This reads like someone asking whether it's safe to leave your front door unlocked again

Fair, and not wrong ๐Ÿ™‚ Appreciate the reminder!

this post was submitted on 26 Jul 2026
18 points (100.0% liked)

Arch Linux

9875 readers
5 users here now

The beloved lightweight distro

founded 6 years ago
MODERATORS