@itsfoss @itsfoss damn. Just yesterday, I was pondering how am enduser could protect themselves from from formerly good but suddenly malicious packages. And I think that "showing how long it's been since a package's PKGBUILD last changed" is not enough. We need a check if there has been any sort of long pause in the maintenance activity of a package. Otherwise, an attacker could just make a benign change, then push the attack update right after so that the check script simply skips over.

Follow

@lexihexi @itsfoss Always read PKGBUILD files. Malicious changes could theoretically be obfuscated, but so far they were pretty obvious.

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml