18
submitted 2 days ago by halm@leminal.space to c/archlinux@lemmy.ml

I haven't heard a peep about the security status of AUR since the headlines about malware injections into thousands of packages. I've ensured that none of my installed software is affected by the attack (to the best of my ability), but I've held off on my regular yay -Syu since then. What has you all done to keep your machine updated but clean?

And is there any update from AUR maintainers that the situation is under control? Most of my installed AUR packages simply don't exist in the official Arch repos, so if not I'd have to look for other sources.

you are viewing a single comment's thread
view the rest of the comments
[-] Creat@discuss.tchncs.de 9 points 1 day ago

It always has been as safe as it always was, assuming you follow basic safety rules. One of them being to read changes, or at least glance at them, but more importantly to not use/install packets that are unmaintained. This possibly includes occasionally checking if those that you have installed are still maintained.

The recent attack has been to take over unmaintained packages, which anyone can do, and use them to inject malware. So only people that had unmaintained packages installed could even be affected. This has not been made impossible. In fact it's mostly unchanged but has been made just slightly harder by requiring (new) aur accounts to have verified mail addresses.

It is kinda hard to really "fix" this, as anyone being able to put packages in the aur is literally the point. So is someone being able to adopt an abandoned package. Changing that would fundamentally alter what the aur is. Maybe it'll eventually be necessary, but what exactly a solution would look like without literally breaking the core idea isn't exactly a trivial question either.

this post was submitted on 26 Jul 2026
18 points (100.0% liked)

Arch Linux

9871 readers
6 users here now

The beloved lightweight distro

founded 6 years ago
MODERATORS