Hi Sam,

In the latter case, it's still unclear to me what's wrong with `revert`
rather than `reset --hard`, as it would still fix the tip of the tree.
It’s true that this would still fix the tip of the tree.

However, the AUR would be permanently hosting malicious code if the commits were merely reverted. This opens up a whole bunch of other issues. For example, one single person in bad faith would be able to cause corporate proxies and search engines all over the place to blocklist the entire domain by merely reporting the cgit URL pointing to the malicious revision. Not to mention the legal ramifications.

I’m not aware of any legitimate platform that keeps malicious or compromised software versions around. They all remove these asap, likely for similar reasons.


Regards
Claudia

Attachment: OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to