Hi Sam,

Malicious package histories are always removed. There is no way I am aware of to examine malicious PKGBUILDs that have been identified and removed.

I am not sure why exactly this is. Perhaps a package maintainer could clarify why overwriting history is SOP.
The only alternative would be deleting the package. But that would bite other contributors, possibly years later, when they check out the tree in an attempt to create a PKGBUILD, get served the malicious tip of the tree, find out there’s prior work, don’t see the malicious line, and run makepkg to see if the old version still works.

That’s why we overwrite history instead.


Regards
Claudia

Attachment: OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to