Comment on Arch Linux AUR Malware Campaign Hits Multiple User-Contributed Packages

<- View Parent
brotundspiele@sh.itjust.works ⁨2⁩ ⁨weeks⁩ ago

On Debian the equivalent to using the AUR would be adding 3rd party apt repositories or manually installing a .deb that you downloaded from some random site on the internet. That is just as vulnerable to the same kind of attack. If you stick to the official repos on Arch, you are just as safe as if you stick to the official repos on Debian.

One could even argue that arch is more secure by providing a central platform like aur, as that’s what allows them to look for malicious packages now.

source
Sort:hotnewtop