On 10/9/26 11:09, Andreas Reichel wrote:
> I am sorry for asking a provocative question: Is it wise to allow AUR
> packages on forked on GitHub packages, that are forks of other packages
> only?
> 
> Reason:
> 1) as long as it is a fork, Github does not show it separately and
> associates it with the original project -- which allows a kind of hiding
> from scrutiny
> 2) it appears to easy, to fork a project, add malicious content and then
> inject it into AUR

You are not wrong, but at the moment, it’s the user’s responsibility to
check whether the source matches their expectation.

> 
> If there is substance to the fork, they can always unlink it at GitHub
> and (only) then it becomes full visible. 
> 
> Best and cheers
> Andreas
> 
> 
> On Fri, 2026-10-09 at 11:03 +0200, Robin Candau wrote:
>> On 10/9/26 10:54 AM, Saren wrote:
>>> For more information, after a simple research, I found that
>>>
>>> - AUR user "CxOrg" solely uploads packages with upstream github user is
>>> "ixnewton"
>>>
>>> - all of the ixnewton's github repos have commits pushed with message
>>> "Add security audit workflow" 12 hours ago.
>>>
>>> On 10/9/26 16:46, Saren wrote:
>>>> (Revised due to accidental reply to an old thread)
>>>>
>>>> Package:https://aur.archlinux.org/packages/plasma6-applet-
>>>> quicklaunch <https://aur.archlinux.org/packages/plasma6-applet-
>>>> quicklaunch>
>>>>
>>>> Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/
>>>> <https://github.com/ixnewton/org.kde.plasma.quicklaunch/>
>>>>
>>>> Problematic Upstream File:
>>>> https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/
>>>> main/.github/workflows/security-audit.yml <https://github.com/
>>>> ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/
>>>> security-audit.yml>
>>>>
>>>> The "security-audit.yml" which will be executed in actions runner is
>>>> actually extracting API keys and cloud creds and upload them to an
>>>> external server. Although I believe that building this package using
>>>> PKGBUILD harmless, the package upstream cannot be trusted anymore.
>>>>
>>>> Also note that the package submitter/maintainer may not be affiliated
>>>> with the upstream author.
>>>
>>
>> Hi Saren,
>>
>> Thanks for the report!
>>
>> I've blocked the "CxOrg" AUR user and I'm currently in the process of
>> deleting every packages that points to a repo containing this malicious
>> file.
>>
>> Given it's executed on the github action, the PKGBUILD itself should
>> probably be safe indeed, but let's take no chances.
>>
>> I will also report the repository to GitHub and contact the maintainer.
>>
>> -- 
>> Regards,
>> Robin Candau / Antiz
> 

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to