(Revised due to accidental reply to an old thread)

Package:https://aur.archlinux.org/packages/plasma6-applet-quicklaunch

Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/

Problematic Upstream File:
https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/security-audit.yml

The "security-audit.yml" which will be executed in actions runner is
actually extracting API keys and cloud creds and upload them to an
external server. Although I believe that building this package using
PKGBUILD harmless, the package upstream cannot be trusted anymore.

Also note that the package submitter/maintainer may not be affiliated
with the upstream author.



Reply via email to