- cross-posted to:
- hackernews@lemmy.bestiver.se
- cross-posted to:
- hackernews@lemmy.bestiver.se
GOTDAMN
As an user of the AUR, this is devastating news to me. I am also guilty of accepting updates without reading the latest changes, even if
yayasks me if I want to. This is a reminder to everyone to only install from the AUR for absolutely necessary stuff only, and only if you trust the maintainer. And to at least have a look if something suspicious is going in with the recent changes in the package recipe. AND to read in the communities and news.I don’t understand why there still no official announcement as a warning from the Archlinux team at https://archlinux.org/news/ . Is there a different place for security news specifically about the AUR to subscribe to?
The fact that the Arch maintainers seem to prefer Reddit over their own fucking news channel is what made me switch from Arch years ago. I got sick of upstream breaking changes fucking my system because they wouldn’t notify people through official channels, only to find it later of /r/archlinux 🙄🙄🙄
since the 2022 grub incident, Arch has done a great job at notifying the news channel when “manual intervention required” AFAIK, and I don’t remember any instances of Arch maintainers only notifying Reddit (and I don’t think they notified Reddit for the grub incident either lol.
It’s been 4 years already? WTF?
deleted by creator
the arch news channel is for breaking changes to arch pacakges (so not the AUR) only. maybe you could subscribe to aur-general@lists.archlinux.org.
I was hoping to subscribe with RSS. Not sure how to subscribe there.
it’s a mailing list, so heads up, if you subscribe you’re also gonna get other discussion like the forums.
https://lists.archlinux.org/mailman3/lists/aur-general.lists.archlinux.org/
There were announcements and security ping in the arch Linux community discord… But I wish they’d be more vocal on this outside discord especially given discords controversy as of late
Thee’s a official Arch Linux D*scord?
No it’s unofficial but it’s I believe the biggest/primary arch Linux community discord .
In their roles chanel you can pick one to get security pings… major ones are typically also everyone pinged but some have those disabled
(hopefully this doesn’t read as blaming the victims instead of the attackers but) I personally don’t think it’s that complicated to read the updates to AUR packages. It’s not any more hard than only commenting after reading the links that people post here instead of just the headlines—which we all do, right?
Wow that’s bad 🫢





