Hello! I've just tried to access deleted AUR repos and found out that
they're still available and can be cloned. Therefore, the packages containing
malware are still dangerous for users.

Is it a bug or a feature?

It’s a feature, and it’s the reason why package maintainers have agreed to rewrite the Git history before deleting affected packages.

Due to human error, the odd package slips through and gets deleted without sanitizing.


Regards
Claudia

Attachment: OpenPGP_0xD11E9FC4F7C9DA3C.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to