346
400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers
(cybersecuritynews.com)
This is a most excellent place for technology news and articles.
And that's why it's fundamentally shit idea on so many levels. Instead of having one person to inspect let's make every single user expert or not to inspect every package each individually. This is fucking retardation at its finest.
The option is to not have it
But who would do that? Do you have security expertise and are volunteering to do that?
Exactly. Let's also not forget it isn't just a matter of inspecting it once, it would be for EVERY update of the script. It would be a major bottleneck to get updates out for any package. There are comments on the AUR site where people can flag issues, so we do have some crowd sourcing, but I'd still not trust it.