I have noticed a suspicious git commit for openconnect-sso [0].

The package has been adopted by user 'rosemariekeller' and includes a new 
commit 'Fix source' [1] that adds a binary 'validator' and executes it using 
'sudo' while packaging.

>From a cursory view at the binary this looks rather suspicious.

[0] https://aur.archlinux.org/packages/openconnect-sso
[1] 
https://aur.archlinux.org/cgit/aur.git/commit/?h=openconnect-sso&id=9d107786fa851c6305dadb3573aab5330a041524

Reply via email to