The thing is I'm going to say is that something like Socket [socket.dev] looks good. The problem is that it doesn't appear to run locally. If we can depend less on the outside world, especially for something like the AUR I think that could be a good thing. I'm am not AUR staff. I'm just giving my dime on this.
Best regards.Please note that a PGP key may be assigned to my email. If this key does not match in between my emails it is a fake email and should be disregarded. Sent with proton mail. PS: Forgot to reply all. On Monday, August 10th, 2026 at 6:39 PM, doublemiu <[email protected]> wrote: > Maria wrote : > Hi, I’ve been speaking with the team at Socket (socket.dev) about whether > their package analysis tools could help the Arch Linux project identify > malicious or suspicious packages in the AUR. Socket already analyzes packages > across ecosystems including npm, PyPI, Maven, Go, and Rust, helping detect > malware and other supply-chain threats. I think that technology and > experience could potentially be useful for the AUR as well. I’m not > affiliated with Socket or Arch Linux. I originally suggested the idea after > seeing supply-chain attacks involving AUR packages, and Socket has expressed > interest in helping improve AUR security. This is only an exploratory > proposal, and I’m not suggesting that Arch needs to adopt anything. I just > think it could be worth a conversation. If an Arch maintainer or staff member > is interested, please contact me and I’d be happy to connect you directly > with the Socket team to discuss what a possible integration or partnership > could look like. Thanks, > Maria > @maria_rcks on Twitter/X > > When i read this i get more and more into conspiracy theries. Please Maria > dont take it personally i dont intent to blame or attack you. > > But my conspiracy theories go 2 ways. First maybe ai agents are making > attacks to get clients for they perfect ai detecting malicious threats > services. > > Second i think is more realistic...dots can match...recent attacks in poland > on enterpraises using ddos by backdoored chinese 2,30 dollar tv chrome cast > dongles....as private sherlock holmes i investigate maybe those 2 earlier > ddos attacks on aur werent just playground before acrion which will come in > different direction with diferent power. Because who cares about some arch > user repository if not only some arch btw users ;) hehe is there any wisdom > about percentage of ips from countries on last ddos attacks on aur? > > > > Sent from Proton Mail for Android.
publickey - [email protected] - 0x55011640.asc
Description: application/pgp-keys
signature.asc
Description: OpenPGP digital signature
