​Socket's npm analysis has proven really effective at curbing supply chain 
attacks. Bringing a similar automated scanning layer to the AUR would be a 
great win for safety, provided Socket provides some kind of 
open-source/community tier. Definitely worth trialing.
From Arch’s perspective: it didn’t stop the June attacks. The malicious package was distributed on npm. AUR was used merely to initiate the deployment. I know it’s a single event, so that’s far from painting the big picture. But the unilateral praise may not look well when that already failed miserably.

From Maria’s report I miss two most important parts. What’s Socket’s interest in doing so, and how are the long-term guarantees secured?

Reply via email to