Requiring manual confirmation for dependencies by default is a good idea, except it doesn't solve the common case where packages that can launch an attack were already installed when you build the malicious PKGBUILD.

--
Cheers,
Aᴀʀᴏɴ

Attachment: OpenPGP_0xCBC3973CD9FC6A16.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to