- 290 Posts
- 1.01K Comments
HaraldvonBlauzahn@feddit.orgto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
1·2 days agoYeah you can go with Nix then.
But it is not by chance that Linux is based on Open Source hardeare support. The alternative is something like MacOS.
I think bugs from library \ version incompatibilities are often hard to recognize.
If you are a long-term Windows user, you already know what it looks like - it is called “DLL Hell”.
HaraldvonBlauzahn@feddit.orgto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
1·2 days agoNah, Guix is dead simple to use. I even trained my pet octopus to build Guix packages after it got bored with the underwater piano :)
HaraldvonBlauzahn@feddit.orgto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
1·2 days agoDid you TeX 3.14159265359 ?
HaraldvonBlauzahn@feddit.orgto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
4·2 days agoDon’t forget that all the Arch users are doing a good part of that testing, too. Arch is a boon to Linux in general.
HaraldvonBlauzahn@feddit.orgto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
1·2 days agoI never said that GitHub was better.
It is arguably harder to take over a package from github or Codeberg.
You could also serve your PKGBUILD from a Gemini server (the Gemini small-web protocol, not the Google AI which is really easy to administer and secure), and sign it with a PGP key. That would be about as secure without depending on a huge US American company.
Using Linux is not a dick measuring contest (and man I hate these threads asking “why is your distro the best?” - it feels like trolling and sowing division and grief to me. A bit like asking a mother “What is your favorite child?”.)
HaraldvonBlauzahn@feddit.orgto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
31·2 days agoUsing Linux is not a dick measuring contest (and man I hate these threads asking “why is your distro the best?” - it feels like trolling and sowing division and grief to me. A bit like asking a mother “What is your favorite child?”.)
But apart from that, I think we can all agree that security of AUR packages is no good enough, and that this deficit is by design.
HaraldvonBlauzahn@feddit.orgto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
41·2 days agoAnyone can publish his PKGBUILD script on their codeberg or github page.
I didn’t knew that before either. I always installed to /usr/local .
I do not understand the whole sentence, can you explain?
Some good advice on installing foreign packages to Debian, and how to keep it functional and secure. Much of it applies to other Linux distrbutions as well.
HaraldvonBlauzahn@feddit.orgOPto
Linux@programming.dev•GNU Guix transactional package manager and distribution — GNU Guix
4·2 days agoUpdated link to the Guix home page: https://guix.gnu.org/
HaraldvonBlauzahn@feddit.orgOPto
Linux@lemmy.world•GNU Guix transactional package manager and distribution — GNU GuixEnglish
3·2 days agoUpdated link to the Guix home page: https://guix.gnu.org/
HaraldvonBlauzahn@feddit.orgOPto
Linux@lemmy.ml•GNU Guix transactional package manager and distribution — GNU Guix
3·2 days agoUpdated link to the Guix home page: https://guix.gnu.org/
HaraldvonBlauzahn@feddit.orgOPto
Linux@lemmy.ml•GNU Guix transactional package manager and distribution — GNU Guix
3·2 days agoYeah, this lemmy webui seems to have a bug/race condition under Sailfish browser, leading to new posts being sent twice. I already removed the other post.
HaraldvonBlauzahn@feddit.orgOPto
Programming@programming.dev•DontBreakDebian - Debian Wiki
4·2 days agoSome good advice on installing foreign packages to Debian, and how to keep it functional and secure. Much of it applies to other Linux distrbutions as well.
Good advice on installing foreign packages to Debian, and how to keep it functional and secure.
HaraldvonBlauzahn@feddit.orgto
Linux@lemmy.ml•The security situation with the Arch Linux AUR got a lot worse
1·2 days agoMost of your suggestions are probably a good idea for the future, but they are not really a solution for a potentially infected system right now.
The only solution for an infected system is to re-install it from scratch, because the integrity of the system is broken. And without any AUR packages, because they can’t be secured in the current form.













So, Arch users do not depend on AUR? If so, that’s easy to fix. Just delete any mention of AUR from the Arch wiki.