Maria @maria_rcks on Twitter/X
Hi, I’ve been speaking with the team at Socket (socket.dev) about
whether their package analysis tools could help the Arch Linux project
identify malicious or suspicious packages in the AUR. Socket already
analyzes packages across ecosystems including npm, PyPI, Maven, Go, and
Rust, helping detect malware and other supply-chain threats. I think
that technology and experience could potentially be useful for the AUR
as well. I’m not affiliated with Socket or Arch Linux. I originally
suggested the idea after seeing supply-chain attacks involving AUR
packages, and Socket has expressed interest in helping improve AUR
security. This is only an exploratory proposal, and I’m not suggesting
that Arch needs to adopt anything. I just think it could be worth a
conversation. If an Arch maintainer or staff member is interested,
please contact me and I’d be happy to connect you directly with the
Socket team to discuss what a possible integration or partnership could
look like. Thanks,
- Exploring Socket security scanning for the AUR Maria
- Exploring Socket security scanning for the AU... Maria
- Re: Exploring Socket security scanning fo... Borna Punda
- Re: Exploring Socket security scannin... Nicolai Dagestad
- Re: Exploring Socket security scannin... mpan
- Re: Exploring Socket security scannin... Cynthia Rey
- Re: Exploring Socket security sca... Borna Punda
- Re: [Possible phishing attem... archlinux . endeared273
- Re: [Possible phishing a... Borna Punda
- Re: Exploring Socket security sca... Maarten de Vries
- Re: Exploring Socket securit... Jonathan Rayne
