Yay 13.0 für Arch Linux: Mehr Kontrolle nach AUR-Sicherheitsvorfällen https://fosstopia.de/yay-13-0/ #Arch #ArchLinux #ArchUserRepository #AUR #Yay

Arch Linux Cracks Down on Malicious Commits in User Repository

Malicious hackers have launched a massive assault on the Arch User Repository, compromising over 1,500 user-submitted packages and forcing the Arch Linux team to temporarily halt new account signups to contain the damage. The attack has been mitigated, but not before highlighting the vulnerability of community-run package repositories.

https://osintsights.com/arch-linux-cracks-down-on-malicious-commits-in-user-repository?utm_source=mastodon&utm_medium=social

#ArchLinux #ArchUserRepository #Aur #MaliciousCommits #PackageCompromise

Arch Linux Cracks Down on Malicious Commits in User Repository

Learn how Arch Linux tackles malicious commits in its User Repository and take action to secure your own online presence today with expert insights.

OSINTSights

OMG, every article about malware in #ArchUserRepository ends with something like "why don't they shut down the repository until all packages are checked?".
That's misunderstanding of what AUR is. Arch offical packages are more curated and actually not affected. Only the user repo is. AUR is like a package forum, where everyone can create and share a package. No authority is curating it closely.
It's like saying "why don't they shut down the arch forum until every mentioned bash command is checked" after somebody breaks their installation by blindly running an evil command like the favourite rm -rf / (don't run this).

And I am not saying, that the attack is fine, and AUR is good tool. I think there should be some kind of maintainer reputation system added and package reputation system improved.

Ce este Arch User Repository (AUR)?

Utilizatorii Arch sunt răsfățați când vine vorba de a descărca programe. Puteți fie să vă obțineți pachetele din depozitul oficial Arch, Snap Store, Flathub, fie eliminați complet necesitatea de a instala programe prin simpla descărcare a AppImage-urilor. Apoi, există o altă opțiune - descărcarea programelor din Arch User Repository (AUR). Dar nu toți utilizatori Arch sunt familiarizați cu aceasta, în special cei nou veniți. Deci, ce este AUR și cum puteți descărca […]

https://comunitatealinux.ro/ce-este-arch-user-repository-aur/

Ce este Arch User Repository (AUR)? – Comunitatea Linux România

I didn't know what I was getting into, but 6 hours in, I am building and compiling Brave using Paru, an Arch User Repository (AUR) helper.

It appears for AUR packages that the `-bin` prefix is for compiled binaries. These will save you a lot of time. I've been warned that Chromium based browsers take days to compile, but I'm compelled to the challenge.

Continuing to compile as I use a backup browser.

#bravebrowser #chromium #paru #archlinux #archuserrepository #compile

What AUR helper do you guys prefer, and why?
#programming #archlinux #arch #linux #aur #archuserrepository
Yay
55.6%
Paru
27.8%
Pikaur
9.3%
Manual / other
7.4%
Poll ended at .
How To Install Yay AUR Helper In Arch Linux - OSTechNix

This guide explains install Yay AUR helper in Arch Linux, EndeavourOS, and Manjaro Linux, and how to use Yay to install packages from AUR.

OSTechNix
Convert Arch Linux Packages To AppImage Format - OSTechNix

This guide explains what is Arch2appimage, how to convert Arch Linux packages to AppImage format with Arch2appimage in Arch Linux.

OSTechNix