• DonutsRMeh@lemmy.world
    link
    fedilink
    arrow-up
    44
    ·
    9 days ago

    I smell something fishy going on. I’ve been using the AUR for a long time and I’m now just hearing of malware?

    • Zikeji@programming.dev
      link
      fedilink
      English
      arrow-up
      73
      ·
      9 days ago

      There’s been malware in the past, not only that - AUR is user submitted. It’s in the name. They warn you to double check what you’re installing. It is functionally similar to running a random installer you found on GitHub.

      It seems like these instances are being intentionally blown out of proportion, but I don’t see what there is to gain by doing that.

      • kadu@lemmy.world
        link
        fedilink
        arrow-up
        60
        arrow-down
        2
        ·
        edit-2
        9 days ago

        It is functionally similar to running a random installer you found

        So basically how Windows users have been acquiring their software for the last 30 years.

      • DonutsRMeh@lemmy.world
        link
        fedilink
        arrow-up
        6
        ·
        9 days ago

        I don’t want to say stupid things, but I have so many theories. I check the shit out of a package before installing it. I even go to the GitHub page and make sure of things.

    • Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      37
      arrow-down
      1
      ·
      9 days ago

      The AUR is made up of user packages

      It isn’t crazy that malware made it in. It is very much a “user at your own risk.” Packages are reviewed but sometimes things slip in.

      • bryndos@fedia.io
        link
        fedilink
        arrow-up
        3
        arrow-down
        3
        ·
        9 days ago

        yeah, you get choice, and its better than a random closed exe in windows.

        Some people have really odd expectations of “free” and “open”.

        Is there a choosingbeggars community to repost this to?

        Just make sure the aur wears a condom when it’s going to fuck you, like your mother told you.

    • Shareni@programming.dev
      link
      fedilink
      arrow-up
      17
      ·
      9 days ago

      It’s an obvious vector for malware, arch by default doesn’t come with it, and users have been warned the entire time to check pkgbuild. There’s nothing fishy, it’s just that arch has enough users to be worth it to hit it.