Socket's npm analysis has proven really effective at curbing supply chain
attacks. Bringing a similar automated scanning layer to the AUR would be a
great win for safety, provided Socket provides some kind of
open-source/community tier. Definitely worth trialing.
From Arch’s perspective: it didn’t stop the June attacks. The
malicious package was distributed on npm. AUR was used merely to
initiate the deployment. I know it’s a single event, so that’s far from
painting the big picture. But the unilateral praise may not look well
when that already failed miserably.
From Maria’s report I miss two most important parts. What’s Socket’s
interest in doing so, and how are the long-term guarantees secured?