I completely agree with [email protected], including the "dependency on outside world" problem. The AUR means Arch *User* Repository, so it would be best if it was run by the users, And since Arch is community run, we are the users, and we are the developers.
On Tue, Aug 11, 2026 at 11:56 AM isameme <[email protected]> wrote: > The thing is I'm going to say is that something like Socket [socket.dev] > looks good. The problem is that it doesn't appear to run locally. If we > can depend less on the outside world, especially for something like the AUR > I think that could be a good thing. > > I'm am not AUR staff. > I'm just giving my dime on this. > Best regards. > Please note that a PGP key may be assigned to my email. *If this key does > not match in between my emails it is a fake email and should be disregarded* > . > > Sent with proton mail. > PS: Forgot to reply all. > On Monday, August 10th, 2026 at 6:39 PM, doublemiu <[email protected]> > wrote: > > Maria wrote : > > Hi, I’ve been speaking with the team at Socket (socket.dev) about whether > their package analysis tools could help the Arch Linux project identify > malicious or suspicious packages in the AUR. Socket already analyzes > packages across ecosystems including npm, PyPI, Maven, Go, and Rust, > helping detect malware and other supply-chain threats. I think that > technology and experience could potentially be useful for the AUR as well. > I’m not affiliated with Socket or Arch Linux. I originally suggested the > idea after seeing supply-chain attacks involving AUR packages, and Socket > has expressed interest in helping improve AUR security. This is only an > exploratory proposal, and I’m not suggesting that Arch needs to adopt > anything. I just think it could be worth a conversation. If an Arch > maintainer or staff member is interested, please contact me and I’d be > happy to connect you directly with the Socket team to discuss what a > possible integration or partnership could look like. Thanks, > Maria > @maria_rcks on Twitter/X > > When i read this i get more and more into conspiracy theries. Please Maria > dont take it personally i dont intent to blame or attack you. > > But my conspiracy theories go 2 ways. First maybe ai agents are making > attacks to get clients for they perfect ai detecting malicious threats > services. > > Second i think is more realistic...dots can match...recent attacks in > poland on enterpraises using ddos by backdoored chinese 2,30 dollar tv > chrome cast dongles....as private sherlock holmes i investigate maybe those > 2 earlier ddos attacks on aur werent just playground before acrion which > will come in different direction with diferent power. Because who cares > about some arch user repository if not only some arch btw users ;) hehe is > there any wisdom about percentage of ips from countries on last ddos > attacks on aur? > > > Sent from Proton Mail <https://proton.me/mail/home> for Android. > > >
