- cross-posted to:
- linux@lemmy.world
- cross-posted to:
- linux@lemmy.world
does a linux mint-using idiot need to worry about this, hypothetically speaking?
Generally not. The AUR stands for Archlinux User Repository. It’s their repo. Unless added as a source manually, you will never see a package from it.
thank you!
This pertains to Arch’s AUR (Arch User Repository). On Mint, nothing you do will interact with the AUR, so you’re perfectly fine.
thank you!
Currently you can use https://github.com/lenucksi/aur-malware-check to do a check if you’re infected. My main server was safe, still haven’t tested on my wayland machine though, I went yolo with that one. No important keys at least are there.
These guys are slacking! Didn’t they read the RFC for this?
https://www.rfc-editor.org/info/rfc3514/ https://en.m.wikipedia.org/wiki/Evil_bit
Amateurs!
They should have some sort of static code scanners on the repos at rest at this point that look for certain patterns and issue warnings.


