▲ 449 ▼ 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers (cybersecuritynews.com) submitted 1 month ago by rafssunny@lemmy.zip to c/technology@lemmy.world 144 comments fedilink hide all child comments
[–] gemakey@lemmy.world 6 points 1 month ago (3 children) Holy shit it's like all of Python. permalink fedilink source parent hideshow 6 child comments replies: [–] Eldritch@piefed.world 7 points 1 month ago (1 child) Yeah, Python has been a massive vulnerability for a long while. And the AUR has similar issues. This is only getting widespread coverage now. But it's always been a risk. permalink fedilink source parent hideshow 2 child comments replies: [–] HaraldvonBlauzahn@feddit.org 1 point 1 month ago Yes, we need a kind of Debian for Python. Part of the solution could be the Guix package manager. Part could be the commercial offerings, like Anaconda. permalink fedilink source parent [–] CaptDust@sh.itjust.works 2 points 1 month ago (2 children) Well, those are mostly extension libraries, stuff "normally" installed using pip. Arch is kind of unique that they encourage using system aur over pip, npm and other package managers. While it is a big radius, none of the python packages stick out to me, but maybe I just haven't encountered the popular ones. permalink fedilink source parent hideshow 4 child comments replies: [–] iocase@lemmy.zip 5 points 1 month ago The attackers specifically targeted orphaned projects on AUR so it's no wonder most of those aren't familiar to us. permalink fedilink source parent [–] esc@piefed.social 3 points 1 month ago (1 child) It isn't really all that unique? Debian does it, el does it, probably almost any popular distro? permalink fedilink source parent hideshow 2 child comments replies: [–] CaptDust@sh.itjust.works 1 point 1 month ago I suppose it's become more common since PEP 668 was introduced, less unique these days. permalink fedilink source parent [–] flying_sheep@lemmy.ml 2 points 1 month ago Arch usually doesn't re-package Python packages that aren't needed for something else, meaning they end up in the AUR. I maintain several there, and when I stop using them I abandon them. I wouldn't be surprised if some of the ones I used to maintain are on the list permalink fedilink source parent
[–] Eldritch@piefed.world 7 points 1 month ago (1 child) Yeah, Python has been a massive vulnerability for a long while. And the AUR has similar issues. This is only getting widespread coverage now. But it's always been a risk. permalink fedilink source parent hideshow 2 child comments replies: [–] HaraldvonBlauzahn@feddit.org 1 point 1 month ago Yes, we need a kind of Debian for Python. Part of the solution could be the Guix package manager. Part could be the commercial offerings, like Anaconda. permalink fedilink source parent
[–] HaraldvonBlauzahn@feddit.org 1 point 1 month ago Yes, we need a kind of Debian for Python. Part of the solution could be the Guix package manager. Part could be the commercial offerings, like Anaconda. permalink fedilink source parent
[–] CaptDust@sh.itjust.works 2 points 1 month ago (2 children) Well, those are mostly extension libraries, stuff "normally" installed using pip. Arch is kind of unique that they encourage using system aur over pip, npm and other package managers. While it is a big radius, none of the python packages stick out to me, but maybe I just haven't encountered the popular ones. permalink fedilink source parent hideshow 4 child comments replies: [–] iocase@lemmy.zip 5 points 1 month ago The attackers specifically targeted orphaned projects on AUR so it's no wonder most of those aren't familiar to us. permalink fedilink source parent [–] esc@piefed.social 3 points 1 month ago (1 child) It isn't really all that unique? Debian does it, el does it, probably almost any popular distro? permalink fedilink source parent hideshow 2 child comments replies: [–] CaptDust@sh.itjust.works 1 point 1 month ago I suppose it's become more common since PEP 668 was introduced, less unique these days. permalink fedilink source parent
[–] iocase@lemmy.zip 5 points 1 month ago The attackers specifically targeted orphaned projects on AUR so it's no wonder most of those aren't familiar to us. permalink fedilink source parent
[–] esc@piefed.social 3 points 1 month ago (1 child) It isn't really all that unique? Debian does it, el does it, probably almost any popular distro? permalink fedilink source parent hideshow 2 child comments replies: [–] CaptDust@sh.itjust.works 1 point 1 month ago I suppose it's become more common since PEP 668 was introduced, less unique these days. permalink fedilink source parent
[–] CaptDust@sh.itjust.works 1 point 1 month ago I suppose it's become more common since PEP 668 was introduced, less unique these days. permalink fedilink source parent
[–] flying_sheep@lemmy.ml 2 points 1 month ago Arch usually doesn't re-package Python packages that aren't needed for something else, meaning they end up in the AUR. I maintain several there, and when I stop using them I abandon them. I wouldn't be surprised if some of the ones I used to maintain are on the list permalink fedilink source parent