RE: https://infosec.exchange/@ifin/116735279416101129
I'm trying to understand the details of AUR processes for submitting PKGBUILDs. In other words, how exactly did this happen? arojas submitted hundreds of changes to PKGBUILD or related files. And they were just...accepted? What am I missing?
Edit: What I missed was this was pure impersonation. The maintainer is fine, but the process was vulnerable to spoofing.

