On 10/9/26 11:09, Andreas Reichel wrote: > I am sorry for asking a provocative question: Is it wise to allow AUR > packages on forked on GitHub packages, that are forks of other packages > only? > > Reason: > 1) as long as it is a fork, Github does not show it separately and > associates it with the original project -- which allows a kind of hiding > from scrutiny > 2) it appears to easy, to fork a project, add malicious content and then > inject it into AUR
You are not wrong, but at the moment, it’s the user’s responsibility to check whether the source matches their expectation. > > If there is substance to the fork, they can always unlink it at GitHub > and (only) then it becomes full visible. > > Best and cheers > Andreas > > > On Fri, 2026-10-09 at 11:03 +0200, Robin Candau wrote: >> On 10/9/26 10:54 AM, Saren wrote: >>> For more information, after a simple research, I found that >>> >>> - AUR user "CxOrg" solely uploads packages with upstream github user is >>> "ixnewton" >>> >>> - all of the ixnewton's github repos have commits pushed with message >>> "Add security audit workflow" 12 hours ago. >>> >>> On 10/9/26 16:46, Saren wrote: >>>> (Revised due to accidental reply to an old thread) >>>> >>>> Package:https://aur.archlinux.org/packages/plasma6-applet- >>>> quicklaunch <https://aur.archlinux.org/packages/plasma6-applet- >>>> quicklaunch> >>>> >>>> Upstream:https://github.com/ixnewton/org.kde.plasma.quicklaunch/ >>>> <https://github.com/ixnewton/org.kde.plasma.quicklaunch/> >>>> >>>> Problematic Upstream File: >>>> https://github.com/ixnewton/org.kde.plasma.quicklaunch/blob/ >>>> main/.github/workflows/security-audit.yml <https://github.com/ >>>> ixnewton/org.kde.plasma.quicklaunch/blob/main/.github/workflows/ >>>> security-audit.yml> >>>> >>>> The "security-audit.yml" which will be executed in actions runner is >>>> actually extracting API keys and cloud creds and upload them to an >>>> external server. Although I believe that building this package using >>>> PKGBUILD harmless, the package upstream cannot be trusted anymore. >>>> >>>> Also note that the package submitter/maintainer may not be affiliated >>>> with the upstream author. >>> >> >> Hi Saren, >> >> Thanks for the report! >> >> I've blocked the "CxOrg" AUR user and I'm currently in the process of >> deleting every packages that points to a repo containing this malicious >> file. >> >> Given it's executed on the github action, the PKGBUILD itself should >> probably be safe indeed, but let's take no chances. >> >> I will also report the repository to GitHub and contact the maintainer. >> >> -- >> Regards, >> Robin Candau / Antiz >
OpenPGP_signature.asc
Description: OpenPGP digital signature
