On 10/08/2026 19:55, Borna Punda wrote:
I'm afraid I don't share the same enthusiasm here. Socket did not flag the npm packages involved in the first wave of malicious AUR package adoptions. I don't exactly remember the timeline, but I vaguely recall Socket still not listing the package as malware after I received a response from the npm security team stating they removed the package...Socket's npm analysis has proven really effective at curbing supply chain attacks.
On 10/08/2026 20:59, Nicolai Dagestad wrote:
-1 from another security professional because socket.dev seems to be a slopware company.
That fits more the image I have of Socket.But even if we put aside Socket, I found that Ralf's comment[1] on the "Crowdsourcing security inspection" thread was quite enlightening; I didn't fully agree with the viewpoint on the first read, but thinking about it more made me realise that it's a very accurate statement. One that I believe also applies here.
On 10/08/2026 16:00, Ralf Mardorf wrote:
so far, the AUR has worked very well based on the principle of "many eyes". What you're suggesting has been working exactly that way for a long time, just without nonsense like a score or gamification. The attacks are annoying, but they were detected immediately upon occurring. As far as detection goes, there’s absolutely no reason to change anything.
The real problem is the attacks themselves, not that they might go undetected. You’re trying to solve a problem that doesn’t need solving, since it’s been working reliably for a long time.
~Cynthia
[1]
https://lists.archlinux.org/archives/list/[email protected]/message/6HCWXEEDOIINTN5VKNZ6M5G73QDNAFPV/
OpenPGP_signature.asc
Description: OpenPGP digital signature
