Hi, I’ve been speaking with the team at Socket (socket.dev) about whether their package analysis tools could help the Arch Linux project identify malicious or suspicious packages in the AUR. Socket already analyzes packages across ecosystems including npm, PyPI, Maven, Go, and Rust, helping detect malware and other supply-chain threats. I think that technology and experience could potentially be useful for the AUR as well. I’m not affiliated with Socket or Arch Linux. I originally suggested the idea after seeing supply-chain attacks involving AUR packages, and Socket has expressed interest in helping improve AUR security. This is only an exploratory proposal, and I’m not suggesting that Arch needs to adopt anything. I just think it could be worth a conversation. If an Arch maintainer or staff member is interested, please contact me and I’d be happy to connect you directly with the Socket team to discuss what a possible integration or partnership could look like. Thanks,
Maria
@maria_rcks on Twitter/X

Reply via email to