Hello! I've just tried to access deleted AUR repos and found out thatthey're still available and can be cloned. Therefore, the packages containingmalware are still dangerous for users.
Is it a bug or a feature?
It’s a feature, and it’s the reason why package maintainers have agreed to rewrite the Git history before deleting affected packages.
Due to human error, the odd package slips through and gets deleted without sanitizing.
Regards Claudia
OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key
OpenPGP_signature.asc
Description: OpenPGP digital signature
