• Hacker News
  • new|
  • comments|
  • show|
  • ask|
  • jobs|
  • embedding-shape 39 minutes

    As always a fair reminder to not install random 3rd party packages/libraries/applications without reviewing them, especially when there is zero vetting. Luckily this was constrained to AUR, which basically is a free-for-all package repository, with users being warned multiple times that it's vital to review anything before you install it, compared to the official repositories.

    `rua` and other similar CLIs make it really easy to review the packages before installing them from AUR too, and if you are doing banking on the same computer, you really have no excuse not to review the software you depend on. Keeping the amount of packages low, only use what you need, also makes this a whole lot simpler when it's time to upgrade.

  • Havoc 8 minutes

    As I undertood it this was mostly orphaned packages?

  • anthonj 22 minutes

    I cringed hard when some people started to make pacman wrappers that could install from AUR directly.

    I've installed stuff from the aur before but most of the times I prefer to skip the middleman and just navigate to the project website. A premade pkgbuild is not convenient enough to take the risk of typoquatting or the tactical npm or pip dependency.

  • new_usemame 8 minutes

    [flagged]

  • tryauuum 37 minutes

    How bad was it?

    graemep 28 minutes

    1,500 packages out of 107,000 so pretty bad, ameliorated by only affecting installs of those in a window of a few days.

    AUR comes with a warning that its up to you to check what you install from there.