How Open Source Projects Change Hands - There are fewer ways to leave your package than to kill it.

https://nesbitt.io/2026/06/16/how-open-source-projects-change-hands.html

How Open Source Projects Change Hands

There are fewer ways to leave your package than to kill it.

Andrew Nesbitt

@andrewnez I think that with this newest twist in the #AUR compromises we might need to simply bar adoption of unmaintained packages.

https://www.phoronix.com/news/Arch-Linux-AUR-Russian-Spam

Russian Spam & Profanities Are Now Plaguing The Arch Linux AUR

After days of dealing with 1,500+ packages in the Arch Linux AUR containing malware, the latest headache in the Arch Linux User Repository is Russian spam and offensive messages.

@andrewnez
There must be
50 ways to leave your package
You could get hacked, Jack
Throw it in the trash can, Stan
Pick a new boy, Roy
Just get yourself free
@andrewnez I plan to yank all the versions of a package that I would rather delete to encourage the last person using it to move on.