We are currently experiencing a high volume of malicious package adoptions and updates in the Arch User Repository.

We are actively working to track down existing malicious commits and attempting to prevent additional malicious commits from being pushed. While this is happening, and while we work to create a more permanent solution, users may see issues with the following:

  • Creating new accounts on the AUR
  • Pushing package updates
  • Adopting or creating new packages

We continue to encourage all users of AUR packages to review all PKGBUILD and install script changes when updating, especially during this time. If you notice suspicious commits to a package that you use, please reach out to Arch staff via the aur-general mailing list with more information.

  • chgxvjh [he/him, comrade/them]@hexbear.net
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 months ago

    Supply chain attacks are a bigger risk than a bit slower patches.

    Of course the reviews would need to be a community process. Might not be a big difference to the regular arch repo then. I think shutting down AUR is a legit option worth exploring.

    • red_giant [comrade/them, he/him]@hexbear.net
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 months ago

      Shutting down AUR is a legit option for sure but it’s not convincing it would solve much.

      You can always just not install packages from AUR if you’d prefer to be immune to the threat.

      Debian is beginning to enforce reproducible builds which is a great step. Requiring source repos to use signed commits would be another.

      Supply chain attacks is not a problem that can be erased but the idea that I cannot install a patch for a critical vulnerability because I’m waiting for community-review seems extreme as well. And who is to say that community review is immune to hijacking anyway?

      If you want professionally vetted code and you also want a library of installable packages then really you want Mac OS and the Mac App Store.