But the malicious actor is still the maintainer. Shouldn't packages be
taken away from malicious maintainers?

On Sun, 02 Aug 2026 08:10:30 +0000, [email protected] wrote
about "[PRQ#85271] Orphan Request for meshcore-open-git Rejected":

> Request #85271 has been Rejected by yan12125 [1]:
> 
> Thanks for the information. The malicious commit is dropped by Antiz.
> 
> [1] https://aur.archlinux.org/account/yan12125/

Attachment: pgpC8Y5jcOPGY.pgp
Description: OpenPGP digital signature

Reply via email to