Comment on AURpocalypse now: a look at the recent AUR attacksparentComments−Ferret74462moI don't think Arch maintainers are responsible for auditing upstream. They package the upstream only.−ChocolateGod2moIf you package software for a distro, you have some responsibility for reviewing what you publish.If you distribute an update that has malware, that is you publishing malware.
Comments
I don't think Arch maintainers are responsible for auditing upstream. They package the upstream only.
If you package software for a distro, you have some responsibility for reviewing what you publish.
If you distribute an update that has malware, that is you publishing malware.