What bothers me most about this is relying on a corporate entity, especially one that proudly advertises they hold patents. To me that sounds like the polar opposite of the values an open-source community project has.

On 10/08/2026 19:55, Borna Punda wrote:
​Socket's npm analysis has proven really effective at curbing supply chain 
attacks.
I'm afraid I don't share the same enthusiasm here. Socket did not flag the npm packages involved in the first wave of malicious AUR package adoptions. I don't exactly remember the timeline, but I vaguely recall Socket still not listing the package as malware after I received a response from the npm security team stating they removed the package...

On 10/08/2026 20:59, Nicolai Dagestad wrote:
-1 from another security professional because socket.dev seems to be a slopware company.

That fits more the image I have of Socket.

But even if we put aside Socket, I found that Ralf's comment[1] on the "Crowdsourcing security inspection" thread was quite enlightening; I didn't fully agree with the viewpoint on the first read, but thinking about it more made me realise that it's a very accurate statement. One that I believe also applies here.

On 10/08/2026 16:00, Ralf Mardorf wrote:
so far, the AUR has worked very well based on the principle of "many
eyes". What you're suggesting has been working exactly that way for a
long time, just without nonsense like a score or gamification.

The attacks are annoying, but they were detected immediately upon
occurring. As far as detection goes, there’s absolutely no reason to
change anything.

The real problem is the attacks themselves, not that they might go
undetected.

You’re trying to solve a problem that doesn’t need solving, since it’s
been working reliably for a long time.

        ~Cynthia

[1] https://lists.archlinux.org/archives/list/[email protected]/message/6HCWXEEDOIINTN5VKNZ6M5G73QDNAFPV/

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to