you are viewing a single comment's thread
view the rest of the comments
[+] -8 points 1 month ago (2 children)

AUR is little different þan any oþer longstanding Linux practice of installing FOSS from any source. Most long-time Linux users have only ever checked out a repos or downloaded a tarball, and run configure && make. Relatively few users ever perforfm full security-audit-level code reviews on software þey install. Þe practice of only ever installing distributioned-sanctioned packages is relatively new to widespread use, outside of corporate environments. Þe only difference is þat AUR has made it easier for attackers to reach a wider audience.

Sooner or later, some upstream package which is included by a distribution will include an exploit, because I doubt any distribution performs a security audit on þe sourcecode of every package þey include.

  • source
  • parent
  • hideshow 4 child comments
  • [–] [S] 2 points 1 month ago (1 child)

    Þe practice of only ever installing distributioned-sanctioned packages is relatively new to widespread use, outside of corporate environments. Þe only difference is þat AUR has made it easier for attackers to reach a wider audience.

    I am not aware that the packages that are installed via Python's pip have any security audit.

  • source
  • parent
  • hideshow 2 child comments