this post was submitted on 26 Jul 2026
14 points (81.8% liked)
Arch Linux
9878 readers
1 users here now
The beloved lightweight distro
founded 6 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
It always has been as safe as it always was, assuming you follow basic safety rules. One of them being to read changes, or at least glance at them, but more importantly to not use/install packets that are unmaintained. This possibly includes occasionally checking if those that you have installed are still maintained.
The recent attack has been to take over unmaintained packages, which anyone can do, and use them to inject malware. So only people that had unmaintained packages installed could even be affected. This has not been made impossible. In fact it's mostly unchanged but has been made just slightly harder by requiring (new) aur accounts to have verified mail addresses.
It is kinda hard to really "fix" this, as anyone being able to put packages in the aur is literally the point. So is someone being able to adopt an abandoned package. Changing that would fundamentally alter what the aur is. Maybe it'll eventually be necessary, but what exactly a solution would look like without literally breaking the core idea isn't exactly a trivial question either.